Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows Process Creation: Suspicious RunAs-Like Command-Line Flag Combination
Flags Windows processes with both target-user and target-command flags in the same command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium91Free2022-11-11PowerShell Get-ADComputer Export of Active Directory Computer Data to File (Windows)
Detects PowerShell running Get-ADComputer (* filter) and exporting results to a file via output/content cmdlets.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium90Free2022-11-10Windows: Detect sftp.exe used as a LOLBIN via -D option
Alerts on Windows executions of sftp.exe using the -D flag with a path argument.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium163Free2022-11-10Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Alerts on Windows Code Integrity Event ID 3077 when an image/driver load is blocked for signing-level or policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh151Free2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-11-09Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
Tim Rauch, Janantha Marasinghe, Elastic (original idea), Huntrule TeamWindowsprocess_creationHigh142Free2022-11-08Windows File Creation: Suspicious LNK Double-Extension Targeted by Document/Image Prefixes
Alerts on Windows-created filenames that end in .lnk while containing hidden-looking double extensions (e.g., .doc. .pdf.)
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsfile_eventMedium103Free2022-11-07Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Identifies Windows successful logons consistent with potential access token impersonation using Advapi and Negotiate.
Michaela Adams, Zach Mathis, Huntrule TeamWindowssecurityMedium60Free2022-11-06Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
Ilya Krestinichev, Huntrule TeamWindowsprocess_creationHigh131Free2022-11-03Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh152Free2022-11-03Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh337Free2022-11-01Windows Scheduled Task Creation with GUID-like Task Name
Alerts on schtasks.exe creating scheduled tasks whose /TN value is wrapped GUID-like braces.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-10-31Windows Image Load: Uncommon VSSAPI DLL (vssapi.dll) by Suspicious Executables
Alerts when uncommon processes load vssapi.dll, a Shadow Copy–related DLL, using image load telemetry with path-based exclusions.
frack113, Huntrule TeamWindowsimage_loadHigh80Free2022-10-31Windows Remote Utilities Host Service Installation via Service Control Manager (EventID 7045)
Alerts on Windows Event 7045 when a "Remote Utilities - Host" service is installed from rutserv.exe -service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium141Free2022-10-31Windows Service Installation via NetSupport Manager (Event ID 7045)
Flags Windows service creation for NetSupport Manager Client32 (client32.exe) using Service Control Manager Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium162Free2022-10-31