Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Application: ScreenConnect RMM File Transfer Activity (Event 201)
Flags ScreenConnect RMM file transfer events on Windows based on provider name, Event ID 201, and transfer action text.
Ali Alwashali, Huntrule TeamWindowsapplicationLow164Free2023-10-10Windows ScreenConnect Remote Command Execution (EventID 200)
Detects ScreenConnect command execution on Windows by matching EventID 200 with an 'Executed command of length' message.
Ali Alwashali, Huntrule TeamWindowsapplicationLow133Free2023-10-10Windows Process Creation: CLI CommandLine References NTFS ::$index_allocation Stream
Flags Windows CLI commands referencing the NTFS ::$index_allocation stream for potential hidden directory activity.
Nasreddine Bencherchali (Nextron Systems), Scoubi (@ScoubiMtl), Huntrule TeamWindowsprocess_creationMedium121Free2023-10-09Windows Hidden Directory Creation Using NTFS $INDEX_ALLOCATION Stream
Alerts on Windows file events creating hidden NTFS content using the '::$index_allocation' alternate stream.
Scoubi (@ScoubiMtl), Huntrule TeamWindowsfile_eventMedium389Free2023-10-09Windows Kerberos KDC: Certificate used without strong user mapping
Alerts on Windows KDC certificate validation events lacking strong certificate-to-user mapping (Event 39/41).
"@br4dy5, Huntrule Team"WindowssystemMedium244Free2023-10-09Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary
Flags Windows process executions that match renamed VS Code tunnel invocation patterns and related internal service startup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2023-09-28Windows Service Registry Key ReadControl Access (Event ID 4663)
Flags READ_CONTROL access requests to service registry keys (\SYSTEM\ControlSet\Services\) via Windows Security Event 4663.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowssecurityLow153Free2023-09-28Windows: AddInUtil.exe LoLBin Executed from Non-Standard Directory
Alerts when AddInUtil.exe (AddInUtil.exe) runs from an uncommon directory path on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium184Free2023-09-18Windows Process Creation: Uncommon AddInUtil.exe Use of AddInRoot/PipelineRoot Paths
Alerts on AddInUtil.exe runs where AddInRoot/PipelineRoot command-line paths deviate from common VSTA locations.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium259Free2023-09-18Windows: Uncommon Child Processes Spawned by Addinutil.exe
Alerts when Addinutil.exe launches an uncommon child process, indicating potential proxy execution abuse.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium273Free2023-09-18Windows AddInUtil.exe Executed with Suspicious AddInRoot or PipelineRoot Parameters
Alerts on AddInUtil.exe runs using uncommon AddInRoot/PipelineRoot values targeting Temp, Desktop, Downloads, or public user paths.
Nasreddine Bencherchali (Nextron Systems), Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationHigh102Free2023-09-18Windows network connections initiated by AddinUtil.exe
Alerts on network connections initiated by Addinutil.exe, which is uncommon for this utility on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsnetwork_connectionHigh431Free2023-09-18Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths
Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-09-15Windows Diskshadow Script Mode Executes Script File with Uncommon .txt Extension
Alerts when diskshadow.exe runs with -s script mode and the script path/command includes an uncommon extension like .txt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium341Free2023-09-15Suspicious Child Process Spawned by Diskshadow.exe (Windows Process Creation)
Alerts on process creation where Diskshadow.exe spawns certutil, cscript, mshta, PowerShell, regsvr32, rundll32, or wscript.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium110Free2023-09-15