Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Alerts when onenote.exe spawns suspicious script or system execution child processes on Windows, consistent with malicious OneNote payload behavior.
Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh60Free2022-10-21Windows DLL Search Order Hijacking: Suspicious DLL Writes to App Dependency Folders
Alerts on suspicious .dll file creation by Office/cmd/scripting processes in AppData and OneDrive/Teams/Slack/VS Code directories.
Tim Rauch (rule), Elastic (idea), Huntrule TeamWindowsfile_eventMedium143Free2022-10-21Windows Process Execution: SafetyKatz HackTool (SafetyKatz.exe)
Alerts when a process running SafetyKatz.exe is created, using image path and embedded file metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2022-10-20Windows Process Creation: Seatbelt.exe PUA Discovery Command-Line Execution
Alerts on Windows process launches of Seatbelt.exe with discovery group arguments and outputfile usage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh222Free2022-10-18PowerShell Set-Acl targeting Windows folder paths on Windows
Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
Detects PowerShell Set-Service commands with SecurityDescriptorSddl SDDL patterns that modify Windows service DACLs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh373Free2022-10-18Windows PowerShell Set-Service SDDL Usage to Hide Services
Flags pwsh Set-Service commands that set a SecurityDescriptorSddl to hide a Windows service from other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-10-17PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Flags PowerShell Set-Service calls that set a SecurityDescriptor SDDL (DCLCWPDTSD) to hide services from other utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh132Free2022-10-17Uncommon Applications Access Windows DPAPI Master Key Files
Alerts on unusual process access to Windows DPAPI master key files under Microsoft\Protect.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium141Free2022-10-17Windows Credential History File Access by Uncommon Applications
Alerts on CREDHIST file access from unexpected application images, indicating potential credential history theft.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium295Free2022-10-17Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Alerts on AD attribute changes adding to msDS-KeyCredentialLink via Windows Security EventID 5136, consistent with shadow credential additions.
Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh246Free2022-10-17Windows process execution: wermgr.exe running outside standard system directories
Alerts when wermgr.exe is launched from a non-standard directory on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh424Free2022-10-14Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2022-10-14Windows Security Logoff Events (Event ID 4634/4647)
Identifies Windows user logoff using Security Event IDs 4634 and 4647.
frack113, Huntrule TeamWindowssecurityInformational204Free2022-10-14