Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: tar.exe Archive Extraction Using -x Flag
Flags Windows process executions of tar.exe with -x to extract compressed archives.
AdmU3, Huntrule TeamWindowsprocess_creationLow339Free2023-12-19Windows tar.exe Used to Create Compressed Archives
Flags tar.exe (or bsdtar) command lines using -c/-r/-u to create or update compressed archives on Windows.
Nasreddine Bencherchali (Nextron Systems), AdmU3, Huntrule TeamWindowsprocess_creationLow103Free2023-12-19Windows Registry: Set LSA NoLMHash to 0 to Enable LM Hash Storage
Flags changes to NoLMHash (DWORD 0) enabling Windows to store LM password hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh173Free2023-12-15Windows Process Creation: Enable LM Hash Storage via Lsa\NoLMHash=0 in Command Line
Flags process command lines that set Lsa\NoLMHash to 0 to enable LM hash storage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh366Free2023-12-15Windows Registry: HVCI disallowed image list modified (HVCIDisallowedImages)
Alerts when Windows HVCI disallowed images registry value is modified, indicating potential driver load policy tampering.
Nasreddine Bencherchali (Nextron Systems), Omar Khaled (@beacon_exe), Huntrule TeamWindowsregistry_setHigh101Free2023-12-05Windows Process Creation: whoami.exe Executed With /all for Full Identity Enumeration
Detects Windows executions of whoami.exe using the /all flag to enumerate full identity details.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2810Free2023-12-04Windows process command line matches WinPwn tool execution keywords
Alerts on Windows process executions with command-line keywords associated with WinPwn (WinPwn.exe/ps1/offline mode).
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh286Free2023-12-04Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsps_scriptHigh152Free2023-12-04Windows Registry: Netsh Helper DLL value added under SOFTWARE\Microsoft\NetSh
Alerts on Windows registry writes under SOFTWARE\Microsoft\NetSh that add .dll helper entries.
Anish Bogati, Huntrule TeamWindowsregistry_setMedium151Free2023-11-28Windows: Netsh helper DLL registration via suspicious registry paths
Flags Netsh helper DLL registration when the DLL path is found in suspicious user/temp-like registry details on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh82Free2023-11-28Windows ImageLoad: Uncommon Process Loads RstrtMgr.dll (Restart Manager)
Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.
Luc Génaux, Huntrule TeamWindowsimage_loadLow141Free2023-11-28Windows Image Load of RstrtMgr.dll by Suspicious Path or User Content
Alerts on RstrtMgr.dll loading from suspicious path contexts using Windows image load telemetry.
Luc Génaux, Huntrule TeamWindowsimage_loadHigh122Free2023-11-28Python-Based Tool LSASS Process Access for Credential Dumping (Windows)
Alerts on process-access attempts to lsass.exe with a Python-related call trace and high granted access.
Bhabesh Raj, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_accessHigh2410Free2023-11-27Windows HackTool Process Access: Detect Access by Common Tool Image Names
Alerts on Windows process access events initiated by processes whose image names match common credential/dumping hack tools.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_accessHigh344Free2023-11-27wusa.exe Execution with Parent in Suspicious Windows Paths
Alerts when wusa.exe is spawned by a parent running from common suspicious Windows directories, excluding .msu-related noise.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh422Free2023-11-26