Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,461 rules
Windows Security Event Add/Remove Computer Account (4741/4743)
Alerts on Windows domain computer account create/delete activity via Security event 4741 and 4743.
frack113, Huntrule TeamWindowssecurityLow80Free2022-10-14Windows: ssh.exe RDP tunneling to :3389 via SSH
Alerts on Windows process executions of ssh.exe that reference RDP port :3389 for SSH tunneling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-10-12Port Forwarding via SSH.EXE on Windows
Flags Windows executions of ssh.exe using remote port forwarding (-R) based on process creation command-line content.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3110Free2022-10-12Windows Credential Manager Vault/File Access by Uncommon Application Images
Alerts on access to Windows credential/vault files by uncommon processes based on image path and file location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium111Free2022-10-11Windows Process Hacker Execution Identified by Image Metadata and Hashes
Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2022-10-10Windows PowerShell Recon Using Get-LocalGroupMember on Local/Well-Known Groups
Flags PowerShell Get-LocalGroupMember usage targeting notable local group names in process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium175Free2022-10-10Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh113Free2022-10-10Windows: NPS (npc.exe) Port Forwarding Proxy Execution via Command-Line Parameters
Flags Windows executions of npc.exe with NPS server, vkey/password, or config=npc command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh455Free2022-10-08Windows Execution of IOX (iex/port forwarding) Tunnel/Proxy Tool via Process Creation
Alerts on Windows process creation for iox.exe with tunneling/proxy forwarding command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2022-10-08Windows Process Creation: SharpWSUS or WSUSpendu Execution via PowerShell Parameters
Detects command-line execution patterns for SharpWSUS or WSUSpendu on Windows.
"@Kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh246Free2022-10-07Windows LPE Attempt via TabTip CLSID Using Microsoft-Windows-DistributedCOM (Event ID 10001)
Alerts when TabTip.exe is started via CLSID/DCOM activation in Windows DistributedCOM EventID 10001.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh61Free2022-10-07Windows Process Creation: GMER Rootkit Tool Execution (gmer.exe)
Flags execution of gmer.exe on Windows when matched by known process hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-10-05PowerShell PSAsyncShell Reverse Shell Activity via Script Block Logging
Detects PowerShell use of PSAsyncShell by matching the tool name in logged script block text.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh121Free2022-10-04Windows Driver Load of Known Vulnerable Drivers by File Name
Alerts when Windows loads a driver whose filename matches a list of known vulnerable drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadLow133Free2022-10-03Windows Malicious Driver Load Identified by Known Bad Driver File Names
Alerts when Windows loads a driver whose file name matches a curated list of known malicious/suspicious drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadMedium152Free2022-10-03