Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,450 rules
Windows: Detect ESENT New Database Created with ntds.dit Written to Suspicious Path
Identifies ESENT EventID 325 where a new database containing ntds.dit is created in suspicious locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium90Free2022-08-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium110Free2022-08-14Windows: Unusual Process Tree for wab.exe and wabmig.exe
Alert on abnormal parent/child process relationships involving wab.exe and wabmig.exe in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh202Free2022-08-12Windows Process Creation: wab.exe or wabmig.exe Run from Non-Default Paths
Alerts when wab.exe or wabmig.exe run from unexpected directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh198Free2022-08-12Windows: User Added to Local Administrators Group via Net or Add-LocalGroupMember
Flags Windows command lines that add a user to the local administrators group via net.exe or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium465Free2022-08-12Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-08-12Windows file write events where executables save files with suspicious script/binary extensions
Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2022-08-12Windows Malicious iphlpapi.dll Dropped in OneDrive/Teams AppData Directory
Flags creation of iphlpapi.dll in the Microsoft AppData area used by OneDrive/Teams, consistent with DLL sideloading attempts.
frack113, Huntrule TeamWindowsfile_eventHigh121Free2022-08-12Windows Service Installation of AnyDesk Software (Service Control Manager 7045)
Flags Windows service creation where AnyDesk appears in the service name and ImagePath via SCM Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssystemMedium353Free2022-08-11Windows Registry: Change to Services\WinSock2\Parameters\AutodialDLL for DLL Persistence
Alerts on registry changes to AutodialDLL under WinSock2 parameters that may enable DLL-based persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh461Free2022-08-10Windows Registry App Paths Default Property Change Using Suspicious Values
Alerts on Windows App Paths registry edits to (Default)/Path with suspicious binaries, scripts, or temp/public locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2022-08-10Windows Startup Folder File Creation with Suspicious Script/Executable Extensions
Alerts on creation of startup-folder files with script/executable extensions commonly used for logon persistence on Windows.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh314Free2022-08-10Windows Registry Persistence via MyComputer \"Default\" Value Modification
Detects changes to Explorer\MyComputer (Default) registry value that can redirect a launched binary for persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh134Free2022-08-09Windows Persistence Attempt via ErrorHandler.cmd in C:\WINDOWS\Setup\Scripts\
Alerts on writing ErrorHandler.cmd to C:\WINDOWS\Setup\Scripts\, a persistence-relevant location on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium292Free2022-08-09Windows file creation for SharpHound/BloodHound collection output filenames
Flags SharpHound/BloodHound default collection export files (zip and multiple JSON datasets) from Windows file events.
C.J. May, Huntrule TeamWindowsfile_eventHigh111Free2022-08-09