Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,449 rules
Windows mshta.exe launched with URL-based arguments (http/https/ftp)
Alerts when mshta.exe is executed with HTTP/HTTPS/FTP URLs in the command line, consistent with remote HTA execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh361Free2022-08-08Windows Registry Persistence: DbgManagedDebugger Debugger Value Added
Alerts on registry sets that add a Debugger value under DbgManagedDebugger, indicating potential crash-triggered persistence.
frack113, Huntrule TeamWindowsregistry_setMedium3810Free2022-08-07Windows Process Creation: Detect Use of 8.3 Short Name in Image Path (~1/~2)
Alerts on Windows process launches whose Image path contains 8.3 short-name markers (~1\ or ~2\), excluding several known benign parents.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium373Free2022-08-07Windows Registry RDP Terminal Services Sensitive Settings Tampering
Flags Windows registry changes to sensitive RDP/Terminal Services settings such as shadowing, remote assistance, security, and InitialProgram.
Samir Bousseaden, David ANDRE, Roberto Rodriguez @Cyb3rWard0g, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh124Free2022-08-06Windows Process Creation: Image contains NTFS 8.3 short filename patterns
Flags process creation events where the Image contains Windows 8.3 short-name patterns (e.g., ~1.exe, ~2.ps1) to evade image-based detections.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium376Free2022-08-06Windows Exploit Guard Controlled Folder Access: Added Allowed Application for Blocked Path
Alerts when an app is added to Exploit Guard’s AllowedApplications list to bypass controlled folder restrictions for risky paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh113Free2022-08-05Windows Registry: Exploit Guard ProtectedFolders Value Deleted
Alerts on deletion of registry values under Exploit Guard Controlled Folder Access ProtectedFolders.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh121Free2022-08-05Windows Process Creation: wusa.exe Cab Extraction From Suspicious Directory Paths
Flags wusa.exe with /extract: originating from common temp/public paths, a potential CAB-based payload unpacking behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-08-05Windows Process Command Line Contains NTFS 8.3 Short Filename Patterns (~1/~2.*)
Detects Windows command lines referencing NTFS 8.3 short names like ~1.exe or ~2.ps1.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium151Free2022-08-05Windows Process Creation: Remove-MpPreference Used to Tamper Windows Defender Settings
Flags process executions that call Remove-MpPreference with Defender tampering-related parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-08-05Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh446Free2022-08-05Windows Suspicious File Creation in AppData Outside Common Subdirectories
Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh82Free2022-08-05Windows Defender Exploit Guard Tamper via Controlled Folder Access AllowedApplications or ProtectedFolders Changes
Alerts on Windefend EventID 5007 when Exploit Guard ProtectedFolders or AllowedApplications lists are modified.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh103Free2022-08-05Windows RDP Tunneling Using plink.exe on Local Port 3389
Alert on plink.exe command lines referencing 127.0.0.1:3389 or port 3389, suggesting potential RDP tunneling on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-08-04Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
Florian Roth (Nextron Systems), Microsoft (idea), Huntrule TeamWindowsprocess_creationHigh90Free2022-08-04