Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows PowerShell Downloading DLLs via Invoke-WebRequest or Invoke-RestMethod
Alerts on PowerShell using web request cmdlets to download an HTTP DLL to disk.
Florian Roth (Nextron Systems), Hieu Tran, Huntrule TeamWindowsprocess_creationMedium70Free2023-03-13PowerShell GzipStream Decompression Attempts on Windows
Detects Windows PowerShell commands using GZipStream and ::Decompress to decompress encoded Gzip data.
Hieu Tran, Huntrule TeamWindowsprocess_creationMedium123Free2023-03-13Windows Wazuh Platform DLL Side-Loading via ImageLoad of libwazuhshared.dll
Alerts on suspicious loading of Wazuh platform DLLs in Windows image load telemetry, excluding common Program Files and Mingw64 patterns.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium151Free2023-03-13Windows Rcdll.dll DLL Sideloading via Image Load Path
Flags rcdll.dll loads from unexpected locations, excluding Visual Studio and Windows Kits directories.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh133Free2023-03-13Windows Sysmon Configuration Update via Sysmon64 Command-Line
Flags execution of Sysmon binaries with '-c', indicating a Sysmon configuration update attempt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-03-09Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh197Free2023-03-08Windows cmd.exe Reads Input from STDIN Using '<' Redirection
Flags cmd.exe invocations with '<' in the command line, indicating stdin/input redirection.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium422Free2023-03-07Windows: Stop a Service with sc.exe via Process Creation (sc.exe stop)
Identifies sc.exe executions that include 'stop' to stop Windows services based on process creation and command line.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow192Free2023-03-05Windows PowerShell Stop-Service Used to Stop a Service
Flags PowerShell executions that include the Stop-Service cmdlet to stop a Windows service.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow131Free2023-03-05Windows: Service stop activity via net.exe command line
Flags Windows processes running net.exe/net1.exe with a command line containing ' stop ' to stop a service.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow100Free2023-03-05Windows: Root Certificate Added Using certutil.exe -addstore
Flags certutil.exe executions that use -addstore with root-related parameters to install a certificate.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationMedium389Free2023-03-05Windows: Root Certificate Installation via CertMgr.EXE (/add root)
Flags CertMgr.EXE used to add a root certificate on Windows by matching /add and root in the command line.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationMedium141Free2023-03-05Windows PowerShell Set-Service StartupType Change to Disabled or Manual
Alerts on PowerShell Set-Service commands changing a service startup type to Disabled or Manual on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium247Free2023-03-04Windows whoami.exe Execution With /FO CSV or Output Redirection
Detects whoami.exe runs that request CSV output or indicate output redirection for saved results.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2023-02-28Windows whoami.exe Group Membership Reconnaissance via /groups Flag
Flags whoami.exe runs that use the /groups option to enumerate current user group memberships and SIDs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-02-28