Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,411 rules
Windows Process Creation: Node.js Executions from Adobe Creative Cloud
Flags Windows executions of Adobe Creative Cloud’s bundled node.exe, excluding typical JS resource paths.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium438Free2022-04-06Windows: Detect Suspicious DumpMinitool.exe Execution via Process Command-Line
Alerts on suspicious command-line usage of DumpMinitool.exe on Windows, leveraging process creation Image, OriginalFileName, and command-line text.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-04-06Windows: Detect DumpMinitool.exe Execution for Process Memory Dumping
Identifies Windows executions of DumpMinitool.exe variants with dump options via process creation telemetry.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-04-06Windows Security: Outgoing Logon (LogonType 9) Using New Credentials (4624)
Flags Windows 4624 LogonType 9 events where new credentials are used for authentication.
Max Altgelt (Nextron Systems), Huntrule TeamWindowssecurityLow141Free2022-04-06Windows Registry: New Root CA or AuthRoot Certificates Added to Certificate Stores
Alerts on registry certificate-store writes adding new Root/CA/AuthRoot certificates as binary blobs.
frack113, Huntrule TeamWindowsregistry_setMedium312Free2022-04-04Windows Registry Key Change Disabling System Restore
Detects registry writes that disable Windows System Restore via policy/config keys set to DWORD 0x00000001.
frack113, Huntrule TeamWindowsregistry_setHigh211Free2022-04-04Windows Registry Service Persistence via SafeBoot Control Keys
Flags Windows registry writes that configure a service to load in Safe Mode (SafeBoot Minimal/Network).
frack113, Huntrule TeamWindowsregistry_setHigh92Free2022-04-04Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
frack113, Huntrule TeamWindowsps_scriptLow153Free2022-04-04Windows Registry Key Changes Disabling PowerShell Logging for Current User
Detects registry changes that disable PowerShell module/script logging and transcription by setting logging keys to DWORD 0.
frack113, Huntrule TeamWindowsregistry_setHigh448Free2022-04-02Windows Registry Change Disabling Hidden and System File Display
Detects registry writes that disable Windows Explorer showing hidden/system files by setting Hidden and ShowSuperHidden to 0x0.
frack113, Huntrule TeamWindowsregistry_setMedium146Free2022-04-02Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage
Flags PowerShell script blocks that use GetTypeFromCLSID followed by ShellExecute.
frack113, Huntrule TeamWindowsps_scriptMedium133Free2022-04-02Windows fsutil.exe Drive Enumeration via Process Execution
Flags fsutil.exe process launches with command lines referencing connected drive enumeration.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow102Free2022-03-29Windows PowerShell IEX Invocation Patterns in Process Creation Command Lines
Alerts on suspicious PowerShell command lines that pipe or otherwise invoke IEX and may include Base64 decoding.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-03-24Windows PowerShell Download and Execution Cradles
Flags PowerShell commands that download remote content and immediately execute it using IEX/Invoke-Expression.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh292Free2022-03-24Windows: reg.exe Registry Tampering of Windows Defender Policy Keys
Detects reg.exe adding Defender DWORD policy values to disable or suppress multiple protection features via Windows registry.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2022-03-22