Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,451 rules
Windows Registry: Set DisallowRun DWORD to 0x1 to Block User Program Execution
Detects Windows registry writes setting Explorer\DisallowRun to DWORD 0x1, a defense-impairment behavior.
frack113, Huntrule TeamWindowsregistry_setMedium126Free2022-08-19Windows Registry: Disable Firewall via EnableFirewall DWORD Policies
Flags registry policy changes that set Windows Firewall EnableFirewall to 0 for Domain or Standard profiles.
frack113, Huntrule TeamWindowsregistry_setMedium235Free2022-08-19Windows Registry: Disable Windows Security Center notifications via UseActionCenterExperience
Alerts on registry updates that set UseActionCenterExperience=0 to disable Windows Security Center notifications.
frack113, Huntrule TeamWindowsregistry_setMedium197Free2022-08-19Windows Registry: Enable RDP Remote Assistance via fAllowToGetHelp
Alerts when Windows enables remote assistance via Terminal Server fAllowToGetHelp (0x1) registry change.
frack113, Huntrule TeamWindowsregistry_setMedium251Free2022-08-19Windows: Uncommon Child Processes Spawned by sigverif.exe
Alerts when sigverif.exe spawns unusual child processes on Windows, excluding common WerFault.exe cases.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium452Free2022-08-19Windows reg.exe Adds or Modifies Suspicious Registry Locations via Command Line
Alerts on reg.exe registry modifications targeting specific Windows policy, security, Defender, and credential-related paths.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-08-19Windows Process Creation: reg.exe Modifying Group Policy Registry Settings
Flags reg.exe commands targeting Group Policy System registry settings related to security and policy refresh.
frack113, Huntrule TeamWindowsprocess_creationMedium91Free2022-08-19Windows PresentationHost.EXE downloading files via URL in command line
Flags PresentationHost.EXE executions whose command line includes http/https/ftp URLs, indicating potential arbitrary file downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium142Free2022-08-19Windows: MSPUB.EXE Downloading Arbitrary Files via HTTP/FTP URIs
Flags MSPUB.EXE executions with HTTP/FTP URLs that may indicate arbitrary file downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3610Free2022-08-19Windows: MSOHTMED.EXE Arbitrary File Download Using HTTP/FTP URLs
Alerts when MSOHTMED.EXE is executed with HTTP/FTP URLs to download an arbitrary file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2022-08-19Windows Register_app.vbs Proxy COM+ Provider Registration via Process Command-Line
Alerts when REGISTER_APP.VBS is executed with -register to register a VSS/VDS provider as a COM+ application.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2022-08-19Windows: Launch-VsDevShell.ps1 Proxy Execution via Process Command Line
Detects command-line usage of Launch-VsDevShell.ps1 with Visual Studio path flags on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium101Free2022-08-19Windows InstallUtil.exe Downloading Files via HTTP/FTP
Flags InstallUtil.exe execution with http/https/ftp URLs indicative of remote file downloads on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium82Free2022-08-19Windows DeviceCredentialDeployment.exe Execution for Process Stealth (T1218)
Flags Windows process execution when DeviceCredentialDeployment.exe starts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium187Free2022-08-19Windows: Suspicious CustomShellHost.exe execution spawned by non-Explorer parent
Alerts on CustomShellHost.exe executions where explorer.exe is not the expected parent process image.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-08-19