Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,405 rules
Windows DISM Online Disable-Feature via DismHost.exe or Dism.exe
Flags Windows DISM/DismHost executions using /Online and /Disable-Feature, a common defense-impairment technique.
frack113, Huntrule TeamWindowsprocess_creationMedium144Free2022-01-16PowerShell ScriptBlock Logging: Set-MpPreference disables Windows Defender scanning or allows threats
Alert on PowerShell Set-MpPreference usage that disables Defender scanning/monitoring or sets threat default actions to Allow.
frack113, elhoim, Tim Shelton (fps, alias support), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh342Free2022-01-16Windows: Deletion of TeamViewer log files
Alerts on deletion of TeamViewer *.log files on Windows, excluding deletions performed by svchost.exe.
frack113, Huntrule TeamWindowsfile_deleteLow161Free2022-01-16Windows rmdir Directory Removal via cmd.exe Execution
Monitors cmd.exe process creation where rmdir is used with /s and/or /q to delete directories and reduce forensic artifacts.
frack113, Huntrule TeamWindowsprocess_creationLow70Free2022-01-15Windows del/erase Command-Line File Deletion via cmd.exe
Flags cmd.exe executions running del/erase for file removal, including common flags like /f, /s, and /q.
frack113, Huntrule TeamWindowsprocess_creationLow229Free2022-01-15Windows PowerShell: Start-Process with -PassThru and -FilePath
Alerts on PowerShell Start-Process calls that include -PassThru and -FilePath, based on ScriptBlockText matches.
frack113, Huntrule TeamWindowsps_scriptMedium131Free2022-01-15Windows rundll32 Execution With Uncommon DLL/CPL/INF Extension in Command Line
Alerts on Windows rundll32 executions whose command lines lack common .cpl/.dll/.inf endings, indicating potential unusual invocation.
Tim Shelton, Florian Roth (Nextron Systems), Yassine Oukessou, Huntrule TeamWindowsprocess_creationMedium4110Free2022-01-13Windows Sysmon Configuration Change (Event ID 16)
Alerts on Sysmon configuration changes via Sysmon Event ID 16 on Windows.
frack113, Huntrule TeamWindowssysmonMedium113Free2022-01-12Windows: Process creation event for Sysmon uninstall using Sysmon -u
Flags attempts to uninstall Sysmon on Windows by running Sysmon with the -u flag.
frack113, Huntrule TeamWindowsprocess_creationHigh439Free2022-01-12PowerShell Script Creates Volume Shadow Copy via Win32_ShadowCopy
Alerts when PowerShell script blocks invoke Win32_ShadowCopy.Create to create a ClientAccessible shadow copy.
frack113, Huntrule TeamWindowsps_scriptHigh171Free2022-01-12Windows ProcDump renamed, copied or moved for stealth evasion
Alerts on ProcDump commands that copy/move or rename dump outputs, including LSASS dump filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-01-11Windows regsvr32 Downloads Remote DLLs via HTTP/HTTPS IP in /i Parameter
Alerts when regsvr32 is invoked with an /i: HTTP/HTTPS IP pattern to fetch remote DLLs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2022-01-11Windows Process Execution: Microsoft.NodejsTools.PressAnyKey.exe Child Spawns
Flags child processes started by Microsoft.NodejsTools.PressAnyKey.exe, which may be abused to run arbitrary binaries.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-01-11Windows mpiexec.exe LOLBin: Flag combination with -n/n 1 for potential arbitrary execution
Alerts on Windows executions of mpiexec.exe with /n 1 or -n 1, correlated to a specific imphash, indicating LOLBin-style behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2022-01-11Windows: Detect devinit.exe MSI download flag combo (-t msi-install, -i http)
Alerts on devinit.exe command lines that combine MSI install with an HTTP download source.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2022-01-11