Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows Process Creation: PowerShell Execution Policy Registry Tampering via CommandLine
Alerts when a process command line references PowerShell ExecutionPolicy registry paths and weaker policy values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2023-01-11Windows BITS Client Job Downloads from Direct IP Addresses
Alerts when Windows BITS Client downloads via HTTP/HTTPS URLs containing direct IP addresses.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsbits-clientHigh352Free2023-01-11Windows AppX Deployment: Uncommon Appx Path Added to Deployment Pipeline
Alerts when an AppX package is queued for processing from uncommon paths or URLs in Windows AppX deployment server events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium101Free2023-01-11Windows AppX Deployment Blocked by Local Policy
Detects blocked AppX package deployments on Windows via AppXDeployment-Server policy-denial Event IDs.
frack113, Huntrule TeamWindowsappxdeployment-serverMedium153Free2023-01-11Windows AppX Package Deployment: Suspicious AppX Installation Attempts by PackageFullName
Alerts on Windows AppX deployment events tied to a known-malicious AppX package identifier.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium162Free2023-01-11Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh101Free2023-01-11Windows AppX Deployment Failure (0x80073cff) Due to Signing Requirements
Alerts on Windows AppX deployments/installations failing with 0x80073cff, consistent with unmet signing requirements.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium162Free2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh426Free2023-01-11Windows AppX deployment blocked by AppLocker (AppXDeployment-Server EventID 412)
Flags AppX package deployment attempts that AppLocker blocked, based on AppXDeployment-Server EventID 412.
frack113, Huntrule TeamWindowsappxdeployment-serverMedium273Free2023-01-11Windows Process Creation: PowerShell Import-Module from Temp/AppData/Public Paths
Alerts on PowerShell Import-Module calls that load modules from Temp, AppData, or Public directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium406Free2023-01-10PowerShell script alias obfuscation via -Value (-join(...))
Flags PowerShell script blocks that set aliases using -Value with a (-join(...)) character-joining obfuscation pattern.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow417Free2023-01-09Windows PowerShell Script Block Alerts for Set-Alias and New-Alias Usage
Alerts on PowerShell scripts that create aliases via Set-Alias/New-Alias, a common obfuscation technique, using ScriptBlockText logging.
frack113, Huntrule TeamWindowsps_scriptLow485Free2023-01-08Windows Suspicious Double-Extension Execution via Parent Command Line
Alerts on Windows processes launched by parents whose image/command line includes disguised double-extension tokens.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh169Free2023-01-06Windows PowerShell Process Creation: Suspicious Base64/Encoded and IEX WebClient Patterns
Detects suspicious PowerShell process command lines using hidden/no-profile, execution-policy bypass, and encoded/Base64 or IEX WebClient download patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-01-05Windows PowerShell: ScriptBlock using security descriptor (Win32_Trustee/Win32_Ace) and LSA data strings
Alerts on PowerShell ScriptBlock text that manipulates security descriptors and LSA-related identifiers, indicating possible persistence behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh352Free2023-01-05