Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,457 rules
PowerShell Adds Windows Defender Exclusions via Add-MpPreference/Set-MpPreference
Flags PowerShell commands that add Windows Defender exclusions using Add-MpPreference/Set-MpPreference with exclusion parameters.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsps_scriptMedium415Free2022-09-16Windows PowerShell Sensitive File Discovery via ScriptBlock Enumeration
PowerShell script blocks using recursive file enumeration that target sensitive file extensions.
frack113, Huntrule TeamWindowsps_scriptMedium2310Free2022-09-16Windows IIS WebServer Access Log Files Deleted
Alerts when IIS access log files (.log) under inetpub\logs\LogFiles\ are deleted.
Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium449Free2022-09-16Windows Security 4663: Access to Microsoft Teams token and local storage files
Identifies non-Teams.exe processes accessing Microsoft Teams cookies or local storage objects on Windows (Event 4663).
"@SerkinValery, Huntrule Team"WindowssecurityHigh121Free2022-09-16Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Detects SharPersist execution on Windows via process name and persistence-related command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh156Free2022-09-15Windows: Service Created by System Using Client with PID 0 (SCM Event 7045)
Alerts on Windows service installation events (SCM EventID 7045) where the client process ID is 0.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowssystemHigh391Free2022-09-15Windows Service Created by Client With PID 0 or Parent PID 0
Alerts on Windows service installs (EID 4697) where the client or parent PID is 0.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh162Free2022-09-15Windows CLI Processes Using Common Weak or Abused Passwords
Alerts when Windows command lines include common weak or reused password values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium156Free2022-09-14Windows PowerShell Disables Windows Firewall Profiles via Set-NetFirewallProfile
Flags PowerShell commands attempting to turn off Windows Firewall profiles using Set-NetFirewallProfile.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium192Free2022-09-14Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium193Free2022-09-14Windows UAC Bypass via Elevated COM interface using ICMLuaUtil
Flags dllhost.exe parent launches tied to elevated COM /Processid GUIDs consistent with UAC bypass behavior on Windows.
Florian Roth (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-13Windows: Taskkill used to terminate ccSvcHst.exe (Symantec Endpoint Protection service impairment)
Flags Windows taskkill /F /IM ccSvcHst.exe executions that can disable Symantec Endpoint Protection services.
Ilya Krestinichev, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh381Free2022-09-13Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution
Flags Windows executions of chisel.exe with client/server tunneling and SOCKS5 reverse arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-09-13Windows Process Creation: 3proxy Proxy Server Execution
Detects execution of 3proxy.exe with local 127.0.0.1 proxy binding on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2022-09-13PowerShell Script Block Logging: Suspicious Windows Event Log Clearing Cmdlets
Flags PowerShell script blocks that call event log clearing cmdlets or ClearLog to impair Windows log visibility.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium92Free2022-09-12