Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,411 rules
Windows PowerShell Active Directory Group Enumeration via Get-AdGroup Cmdlet
Flags PowerShell script blocks that call Get-ADGroup with -Filter to enumerate Active Directory groups.
frack113, Huntrule TeamWindowsps_scriptLow163Free2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
frack113, Huntrule TeamWindowsps_scriptLow357Free2022-03-17PowerShell Get-ADUser Enumeration Using UserAccountControl DONT_REQ_PREAUTH Flag
Flags Get-ADUser PowerShell scripts enumerating accounts by UserAccountControl DONT_REQ_PREAUTH (4194304).
frack113, Huntrule TeamWindowsps_scriptMedium131Free2022-03-17Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh133Free2022-03-16Windows Remote Thread Creation Targeting Uncommon System Image Processes
Alert on Windows remote thread creation events targeting a predefined list of uncommon processes by image path.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_remote_threadMedium141Free2022-03-16Windows schtasks.exe Create Executes File from AppData\Local
Alerts on schtasks.exe creating tasks that run payloads from C:\Users\<user>\AppData\Local.
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh196Free2022-03-15Windows Process Creation: Suspicious for/foreach Scan Loop with nslookup or ping
Alerts on Windows command lines using for/foreach loops that also run nslookup or ping, consistent with host scanning.
frack113, Huntrule TeamWindowsprocess_creationMedium113Free2022-03-12Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh215Free2022-03-12Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh327Free2022-03-11Windows Process Creation: OfflineScannerShell.exe mpclient.dll DLL Sideloading Risk
Detects OfflineScannerShell.exe launched with an unexpected current directory that could enable mpclient.dll sideloading.
frack113, Huntrule TeamWindowsprocess_creationMedium393Free2022-03-06Windows Process Creation: Replace.exe with -a argument
Detects Replace.exe executions that include the -a argument, which may be used for file replacement.
frack113, Huntrule TeamWindowsprocess_creationMedium265Free2022-03-06Windows Suspicious UltraVNC Command Line With Auto-Reconnect Flags
Alerts on UltraVNC execution using -autoreconnect with -connect and -id in the Windows command line.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh151Free2022-03-04PowerShell Base64 Encoded MpPreference Command Lines for Windows Defender Modification
Detects PowerShell Base64 command lines referencing Add-MpPreference/Set-MpPreference to modify Microsoft Defender AV settings.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh147Free2022-03-04Windows Hacktool Execution Flagged by Imphash in Process Creation
Alerts on Windows process executions where the import hash matches known hacktool binaries, even if renamed.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical486Free2022-03-04