Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,407 rules
Windows: reg.exe Adds Windows Defender Exclusion Paths via Registry Value Update
Detects reg.exe commands that modify Windows Defender/Microsoft Antimalware exclusion path registry entries.
frack113, Huntrule TeamWindowsprocess_creationMedium455Free2022-02-13Windows esentutl.exe Browser Data Collection via -r and WebCache path
Flags esentutl.exe runs with -r and WebCache references, indicating potential browser data collection.
frack113, Huntrule TeamWindowsprocess_creationMedium91Free2022-02-13Windows File Creation of ScreenConnect Temporary Installation Artefact
Flags Windows file events referencing temporary ScreenConnect artefacts under the \Bin\ScreenConnect.* path.
frack113, Huntrule TeamWindowsfile_eventMedium143Free2022-02-13GoToAssist Temporary File Drop in Windows Temp Directory
Flags creation of GoToAssist Remote Support Expert temp installation artefacts under Windows AppData\Temp.
frack113, Huntrule TeamWindowsfile_eventMedium444Free2022-02-13Windows schtasks Creates Registry-Backed Base64 PowerShell Payload via Encoded Command
Flags schtasks.exe scheduling that triggers PowerShell to decode a base64 payload pulled from Windows Registry.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-02-12Windows reg.exe Used to Modify RDP Terminal Server Registry Values
Flags reg.exe command lines that modify Terminal Server registry values controlling RDP enablement and behavior.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh2710Free2022-02-12PowerShell DirectorySearcher AD Computer Enumeration via System.DirectoryServices.DirectorySearcher
Flags PowerShell DirectorySearcher queries that load directory properties and enumerate results from Active Directory.
frack113, Huntrule TeamWindowsps_scriptMedium201Free2022-02-12Windows process creation: flag suspicious program names and PowerShell script indicators
Alerts on suspicious Windows process image names and PowerShell command-line script/tool patterns commonly used in malicious tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-02-11Windows LogMeIn LMIGuardianSvc Execution Associated with Remote Access Tools
Flags Windows process launches identified as LogMeIn LMIGuardianSvc by Description/Product/Company attributes.
frack113, Huntrule TeamWindowsprocess_creationMedium375Free2022-02-11AnyDesk Executable Execution on Windows
Detects AnyDesk-related process launches on Windows by matching executable names and AnyDesk product metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium70Free2022-02-11Windows File Creation Indicators for Local SAM Database Exports
Alerts on Windows file creations with filenames indicative of a local SAM export or backup artifact.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh198Free2022-02-11Windows Recent Files Shortcut Points to ISO/IMG/VHD Mount Images
Flags Windows Recent Items entries that reference ISO/IMG/VHD/VHDX mount shortcuts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventMedium143Free2022-02-11Windows File Events: AnyDesk user.conf and system.conf Temporary Artefacts
Identifies Windows file writes of AnyDesk user.conf or system.conf in AppData\Roaming.
frack113, Huntrule TeamWindowsfile_eventMedium101Free2022-02-11Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Alerts on command lines using TrolleyExpress.exe PID parameters consistent with LSASS memory dumping on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-02-10Windows LSASS memory access from TrolleyExpress/ProcessDump/dump64 processes
Alerts on Windows processes attempting to access lsass.exe from TrolleyExpress.exe, ProcessDump.exe, or dump64.exe with dump-like access rights.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh141Free2022-02-10