Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,411 rules
Windows LSA PPL Protection Setting Modification via reg.exe or PowerShell Command Line
Flags Windows command lines that alter LSA PPL-related Control\Lsa registry settings using reg.exe/PowerShell property changes.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium132Free2022-03-22Windows Suspicious Parent Processes: Unusual Child Creation by System Utilities
Alerts when predefined suspicious Windows parent executables spawn unusual or unrecognized child processes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2022-03-21Windows Service Control Manager: HackTool Service Installation or Start via Suspicious Service Names
Detects Windows service creation/start events tied to hacktool-like service names or ImagePath indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh362Free2022-03-21Windows Registry Policy Modification for Explorer UI Function Disabling
Flags Windows Explorer policy registry value writes (DWORD 0x1) that disable Explorer functions or UI elements.
frack113, Huntrule TeamWindowsregistry_setMedium418Free2022-03-18Windows Registry Defense Impairment via Explorer Hide* Policy Values
Flags registry set events that change Explorer hide-related DWORD values under Windows policy keys to impair user visibility.
frack113, Huntrule TeamWindowsregistry_setMedium3710Free2022-03-18Windows Registry Policy Change to Disable/Impair Internal Tools and UI Features
Detects registry policy edits that disable Windows tools/features or alter related system behavior via specific DWORD values.
frack113, Nasreddine Bencherchali (Nextron Systems), CrimpSec, Huntrule TeamWindowsregistry_setMedium162Free2022-03-18Windows Service Installation via Scripted ImagePath Indicators (Event 7045)
Identifies suspicious Windows service installations that embed script host execution via Event ID 7045 ImagePath patterns.
pH-T (Nextron Systems), Huntrule TeamWindowssystemHigh446Free2022-03-18Windows Service Installation with Suspicious ProgramData/Root Executable Image Paths
Flags Windows service installs (Event 7045) that reference suspicious EXE paths in ProgramData or directly under C:\.
pH-T (Nextron Systems), Huntrule TeamWindowssystemHigh93Free2022-03-18Windows Service Installation with PowerShell Download and Hidden Execution
Alerts on Windows service creation (7045) with ImagePath patterns indicating hidden/staged command execution.
pH-T (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh152Free2022-03-18Windows Registry Run Key Entries Containing PowerShell Execution Strings
Alerts when registry Run key value data contains PowerShell launch or encoded download/execution strings on Windows.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setMedium91Free2022-03-17Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Flags web server processes spawning child commands consistent with credential dumping, exfiltration, and privilege changes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-03-17Windows PktMon.exe Process Execution (pktmon.exe / PktMon.exe)
Alerts on Windows executions of PktMon.exe based on process creation image name and OriginalFileName.
frack113, Huntrule TeamWindowsprocess_creationMedium162Free2022-03-17Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
frack113, Huntrule TeamWindowsps_scriptLow133Free2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
frack113, Huntrule TeamWindowsps_scriptLow404Free2022-03-17Windows PowerShell Directory Enumeration via Get-ChildItem and Output Redirection
Flags PowerShell directory enumeration patterns using Get-ChildItem, error suppression, and appended output to a file.
frack113, Huntrule TeamWindowsps_scriptMedium215Free2022-03-17