Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows Password Change via ksetup.exe /setcomputerpassword
Alerts on Windows ksetup.exe executions that set a computer password via /setcomputerpassword.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-04-06Windows Defender Real-Time Protection Error or Restart (windefend Event 3002/3007)
Alerts on windefend events showing Defender Real-Time Protection feature errors (3002) or restarts (3007).
Nasreddine Bencherchali (Nextron Systems), Christopher Peacock '@securepeacock' (Update), Huntrule TeamWindowswindefendMedium3410Free2023-03-28Windows Process Creation: Sysinternals PsSuspend Targeting msmpeng.exe
Alerts on execution of Sysinternals PsSuspend with command line referencing msmpeng.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh488Free2023-03-23Windows Sysinternals PsSuspend Process Execution
Alerts on execution of Sysinternals PsSuspend on Windows via process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium90Free2023-03-23Windows DLL sideloading: iviewers.dll loaded from non-Windows Kits paths
Alerts on unexpected loads of iviewers.dll outside Windows Kits paths, consistent with DLL sideloading attempts.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2023-03-21Windows PowerShell File Dropper Activity: Creating Executables or Script Files
Alerts when PowerShell writes .exe/.dll or script-like files, consistent with binary/script staging or dropping.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium171Free2023-03-17Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
Alerts on svchost.exe launching rundll32.exe to run davclnt.dll DavSetCookie for WebDav over a non-local IP.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2023-03-16Windows Registry: Hypervisor Enforced Code Integrity Enabled DWORD Set to 0
Alerts when HVCI-related registry values are set to 0, indicating Hypervisor Enforced Code Integrity has been disabled.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsregistry_setHigh141Free2023-03-14Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-03-14Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Flags Sysinternals ADExplorer running with "snapshot" to create a local Active Directory database copy.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-03-14Windows AD Structure Export Using ldifde.exe with -f
Flags ldifde.exe executions using -f that indicate Active Directory structure export from a Windows host.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-03-14Windows Process Creation: dotnet-dump.exe collect Flag
Flags dotnet-dump.exe executions using the collect parameter, which may indicate memory dumping of sensitive processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium172Free2023-03-14Windows: Detect csvde.exe Active Directory export to CSV
Flags csvde.exe executions on Windows that include -f, consistent with exporting Active Directory data for discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium247Free2023-03-14Windows Registry Event for Potential Qakbot/IceID Persistence Key
Alerts on Windows registry events referencing a specific \\Software\\firm\\soft\\Name key suffix linked to Qakbot/IceID-like activity.
Hieu Tran, Huntrule TeamWindowsregistry_eventHigh132Free2023-03-13Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
Hieu Tran, Huntrule TeamWindowsprocess_creationHigh91Free2023-03-13