Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows reg.exe Changes Desktop Background Policy Values
Alerts when reg.exe is used to modify Windows registry settings that control wallpaper or desktop background behavior.
Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule TeamWindowsprocess_creationMedium154Free2023-12-21Windows Process Execution of Renamed cloudflared.exe with Tunnel/Run Command Arguments
Alerts on Windows process executions of renamed cloudflared with tunnel run/cleanup command-line arguments or matching SHA-256 hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2023-12-20Windows Execution of cloudflared for Cloudflare Try/Quick Tunnel Ad-hoc Tunneling
Flags execution of cloudflared on Windows with -url arguments consistent with Cloudflare Quick Tunnel setup.
Sajid Nawaz Khan, Huntrule TeamWindowsprocess_creationMedium120Free2023-12-20Windows execution of cloudflared.exe from a non-default directory
Alerts on cloudflared.exe executions from unusual paths on Windows, excluding standard Program Files locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium476Free2023-12-20Windows DNS Queries for Cloudflared Tunnel Domains
Alerts on Windows DNS queries for domains ending with common Cloudflared tunnel hostnames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryMedium293Free2023-12-20Windows: tar.exe Archive Extraction Using -x Flag
Flags Windows process executions of tar.exe with -x to extract compressed archives.
AdmU3, Huntrule TeamWindowsprocess_creationLow339Free2023-12-19Windows tar.exe Used to Create Compressed Archives
Flags tar.exe (or bsdtar) command lines using -c/-r/-u to create or update compressed archives on Windows.
Nasreddine Bencherchali (Nextron Systems), AdmU3, Huntrule TeamWindowsprocess_creationLow103Free2023-12-19Windows Registry: Set LSA NoLMHash to 0 to Enable LM Hash Storage
Flags changes to NoLMHash (DWORD 0) enabling Windows to store LM password hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh173Free2023-12-15Windows Process Creation: Enable LM Hash Storage via Lsa\NoLMHash=0 in Command Line
Flags process command lines that set Lsa\NoLMHash to 0 to enable LM hash storage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh366Free2023-12-15Windows Registry: HVCI disallowed image list modified (HVCIDisallowedImages)
Alerts when Windows HVCI disallowed images registry value is modified, indicating potential driver load policy tampering.
Nasreddine Bencherchali (Nextron Systems), Omar Khaled (@beacon_exe), Huntrule TeamWindowsregistry_setHigh101Free2023-12-05Windows Process Creation: whoami.exe Executed With /all for Full Identity Enumeration
Detects Windows executions of whoami.exe using the /all flag to enumerate full identity details.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2810Free2023-12-04Windows process command line matches WinPwn tool execution keywords
Alerts on Windows process executions with command-line keywords associated with WinPwn (WinPwn.exe/ps1/offline mode).
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh316Free2023-12-04Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsps_scriptHigh172Free2023-12-04Windows Registry: Netsh Helper DLL value added under SOFTWARE\Microsoft\NetSh
Alerts on Windows registry writes under SOFTWARE\Microsoft\NetSh that add .dll helper entries.
Anish Bogati, Huntrule TeamWindowsregistry_setMedium151Free2023-11-28Windows: Netsh helper DLL registration via suspicious registry paths
Flags Netsh helper DLL registration when the DLL path is found in suspicious user/temp-like registry details on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh82Free2023-11-28