Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,442 rules
Windows: Execution of .xbap via PresentationHost.exe from Uncommon Paths
Alerts when PresentationHost.exe launches a .xbap file from a non-standard location on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium319Free2022-07-01Windows: Execution of ScriptRunner.exe with appvscript Argument
Flags ScriptRunner.exe executions that include the " -appvscript " parameter in the command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2022-07-01Windows: Suspicious LSASS handle access via svchost.exe call trace to seclogon.dll
Flags svchost.exe attempting LSASS access (granted access 0x14c0) with seclogon.dll in the call trace.
Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh294Free2022-06-29Windows: assoc.exe Changes File Extension Handler to exefile
Alerts on cmd.exe running assoc to set file extension handlers to exefile, indicating possible persistence via file associations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-06-28Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Flags bitsadmin.exe file downloads that target suspicious folders using /transfer, /create, and /addfile command-line parameters.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-06-28Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Flags bitsadmin.exe commands that transfer or add files with suspicious extensions based on process creation command-line content.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2022-06-28Windows BITSAdmin Downloads from File-Sharing Domains
Alerts on BITSAdmin downloads from popular file-sharing domains when transfer/create/addfile command-line flags are present.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-06-28Windows Process Creation: bitsadmin Download Using Direct IP URL
Alerts when bitsadmin.exe is used to download via a direct IP address in the command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-06-28Windows attrib.exe sets hidden system file attribute (+s) on suspicious paths and script/executable extensions
Flags attrib.exe usage with +s to mark .exe/.dll and script files in public/temp/user-writable locations as system files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-06-28PowerShell disables or removes ETW Trace via Set-EtwTraceProvider or Remove-EtwTraceProvider
Flags PowerShell commands that remove or disable ETW trace providers to impair Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-06-28Windows BITS Transfer Job Download to Suspicious File Paths
Flags new Windows BITS transfer jobs that save downloaded files into predefined suspicious paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientHigh2810Free2022-06-28Windows BITS Client Downloads From File-Sharing Domains
Alerts on Windows BITS transfers (EventID 16403) that download from known file-sharing/content hosting domains.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientHigh122Free2022-06-28Windows dllhost.exe Launched With No Command-Line Arguments
Alerts on dllhost.exe being executed with no command-line arguments, a rare pattern that may indicate stealthy or injected activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-06-27Windows HandleKatz: Duplicate LSASS Handle via Process Access with Handle Duplication Rights
Flags HandleKatz-style behavior duplicating an existing LSASS handle using PROCESS_DUP_HANDLE and ntdll.dll call trace.
Bhabesh Raj (rule), @thefLinkk, Huntrule TeamWindowsprocess_accessHigh275Free2022-06-27Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-06-27