Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,443 rules
Windows Registry: Hidden User via Winlogon SpecialAccounts Userlist Value 0
Alerts on Windows registry updates that set Winlogon SpecialAccounts Userlist to DWORD 0 to hide users.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsregistry_setHigh141Free2022-07-12Windows: Base64-Encoded PE “MZ” Header Present in Command Line
Alerts when Windows command lines include Base64 strings matching a PE “MZ” header.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh278Free2022-07-12Windows: Local user creation via net.exe with expires:never
Flags net.exe user add commands that set expires:never for local account persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-07-12Windows: Detect Suspicious mofcomp.exe Execution from Scripts or Temp Paths
Flags mofcomp.exe runs spawned by script interpreters or using temp/AppData paths, with exclusions for WmiPrvSE .mof-related activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-07-12Windows cmd.exe Output Redirection to User Writable Paths
Flags cmd.exe commands that redirect output (>) into temp/AppData and other commonly targeted directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium124Free2022-07-12Windows MSSQL xp_cmdshell Setting Change (EventID 15457)
Flags MSSQL xp_cmdshell setting changes using Windows application EventID 15457 events containing 'xp_cmdshell'.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh2210Free2022-07-12Windows MSSQL xp_cmdshell Command Execution via Application Event 33205
Alerts when SQL Server xp_cmdshell is invoked to execute commands, using Windows application EventID 33205 data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh156Free2022-07-12Windows PowerShell: Detect Command Lines with Suspicious UTF-16 Base64 Obfuscation Patterns
Alerts on PowerShell command lines containing suspicious UTF-16/Base64 obfuscation fragments indicative of hidden script logic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2022-07-11Windows DNS Queries to Remote Support and Remote Access Domains From Non-Browser Processes
Alert on DNS lookups for remote access service domains from non-browser executables, including RustDesk subdomains.
frack113, Connor Martin, Huntrule TeamWindowsdns_queryMedium122Free2022-07-11PowerShell TCP Tunnel Indicators: HttpWebRequest and TcpListener Usage (Windows
Flags PowerShell scripts referencing TcpListener/AcceptTcpClient and HttpWebRequest as potential TCP tunneling behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium162Free2022-07-08Windows: Detect Named Pipe Creation with Koh Default Names
Alerts on Windows named pipe creation with Koh default identifiers in the pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical441Free2022-07-08Windows PowerShell: Import-Module From Temp, AppData, or Public Directories
Detects PowerShell module imports (Import-Module/ipmo) from Temp, AppData, or Public directories via Script Block Logging.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium153Free2022-07-07Windows Registry Changes Disabling Windows Defender Event Log Channel
Detects registry changes that disable the Windows Defender Operational event log channel by setting its Enabled DWORD to 0.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh394Free2022-07-04Windows Registry Event Log Tampering by Disabling WINEVT Channel Enabled Key
Flags registry changes that set WINEVT channel Enabled to 0x00000000 to disable Windows event logging.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh223Free2022-07-04Windows UAC Bypass via IDiagnosticProfileUAC Triggered from DllHost.exe
Flags elevated process creation where DllHost.exe launches using the specific IDiagnosticProfileUAC /Processid value.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh257Free2022-07-03