Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows PingCastle Execution From Suspicious Parent Processes
Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2024-01-11Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Alerts on Windows execution of PingCastle with full healthcheck and AD/security scanner command-line options.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium152Free2024-01-11Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
Alerts on Windows loading of .cpl control panel items from uncommon paths instead of standard system directories.
Anish Bogati, Huntrule TeamWindowsimage_loadHigh284Free2024-01-09Windows WFP 5157: Connection Blocked for EDR Agent Binaries
Flags WFP blocked connections (EventID 5157) when an EDR/security agent binary is the blocked application.
"@gott_cyber, Huntrule Team"WindowssecurityHigh263Free2024-01-08Windows forfiles.exe Spawned cmd.exe from Non-System Location
Alerts on forfiles.exe running outside system paths and spawning cmd.exe with a forfiles-encoded command pattern.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsprocess_creationHigh438Free2024-01-05Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Alerts on Windows Filtering Platform policy change events containing "RonPolicy" consistent with NoFilter abuse.
Stamatis Chatzimangou (st0pp3r), Huntrule TeamWindowssecurityHigh191Free2024-01-05Windows Process Creation: EDRSilencer Executed
Flags execution of EDRSilencer.exe on Windows based on process image and identifying metadata.
"@gott_cyber, Huntrule Team"Windowsprocess_creationHigh437Free2024-01-02Windows Process Execution of dotnet-trace.exe Child via '-- collect' Arguments
Alerts on dotnet-trace.exe executions with '-- ' and 'collect' command-line arguments that may proxy child process execution.
Jimmy Bayne (@bohops), Huntrule TeamWindowsprocess_creationMedium389Free2024-01-02Windows Registry Persistence via AppCompatFlags Layers REGISTERAPPRESTART
Detects registry persistence settings that include the AppCompat layer "REGISTERAPPRESTART" on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium229Free2024-01-01Windows Registry Change to Desktop Wallpaper Policy or Settings
Detects Windows registry updates that enforce or change the desktop wallpaper and restrict user control.
Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule TeamWindowsregistry_setMedium82Free2023-12-21Windows reg.exe Changes Desktop Background Policy Values
Alerts when reg.exe is used to modify Windows registry settings that control wallpaper or desktop background behavior.
Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule TeamWindowsprocess_creationMedium144Free2023-12-21Windows Process Execution of Renamed cloudflared.exe with Tunnel/Run Command Arguments
Alerts on Windows process executions of renamed cloudflared with tunnel run/cleanup command-line arguments or matching SHA-256 hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-12-20Windows Execution of cloudflared for Cloudflare Try/Quick Tunnel Ad-hoc Tunneling
Flags execution of cloudflared on Windows with -url arguments consistent with Cloudflare Quick Tunnel setup.
Sajid Nawaz Khan, Huntrule TeamWindowsprocess_creationMedium120Free2023-12-20Windows execution of cloudflared.exe from a non-default directory
Alerts on cloudflared.exe executions from unusual paths on Windows, excluding standard Program Files locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium466Free2023-12-20Windows DNS Queries for Cloudflared Tunnel Domains
Alerts on Windows DNS queries for domains ending with common Cloudflared tunnel hostnames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryMedium283Free2023-12-20