Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,405 rules
Windows Browser Process Spawned with Inline URL Pointing to Suspicious File Extension
Flags Windows browser processes launched with an inline HTTP URL pointing to files with suspicious extensions.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium364Free2022-01-11Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Alerts on creation of ntds.dit on Windows when the creator process image/path is uncommon or located in suspicious directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh131Free2022-01-11Windows WScript/CScript File Write With Script Extensions to Temp or Startup Paths
Alerts when WScript/CScript writes script files (.js/.vbs/.wsf/.wsh, etc.) into common temp or Startup directories.
Tim Shelton, Huntrule TeamWindowsfile_eventHigh459Free2022-01-10Windows Registry: Disable Microsoft Defender Firewall by Setting EnableFirewall to 0
Flags Windows Registry changes that disable Defender firewall by setting EnableFirewall DWORD to 0.
frack113, Huntrule TeamWindowsregistry_setMedium153Free2022-01-09Windows netsh Enables Defender Firewall Group Rules via advfirewall set rule group new enable=Yes
Flags netsh.exe command lines that create and enable Microsoft Defender Firewall group rules (enable=Yes).
frack113, Huntrule TeamWindowsprocess_creationMedium249Free2022-01-09Windows: AppCmd disables IIS HTTP logging via dontLog=true
Flags appcmd.exe commands that disable IIS HTTP logging by setting httplogging to dontLog:true.
frack113, Huntrule TeamWindowsprocess_creationHigh353Free2022-01-09Windows Dynamic C# Compilation Generates .cmdline Artifact
Detects Windows file events where dynamic C# compilation produces a .cmdline artefact.
frack113, Huntrule TeamWindowsfile_eventLow417Free2022-01-09Windows: Detect mstsc.exe Remote Desktop connection via /v flag
Flags Windows RDP connection attempts started by mstsc.exe using the /v: target argument, excluding WSL helper scenarios.
frack113, Huntrule TeamWindowsprocess_creationMedium151Free2022-01-07Windows HackTool Activity: Evil-WinRM Ruby Process with -i, -u, -p Arguments
Flags Ruby processes launched with Evil-WinRM parameters (-i, -u, -p), indicative of WinRM remote access attempts.
frack113, Huntrule TeamWindowsprocess_creationMedium2910Free2022-01-07PowerShell script exfiltration using Invoke-WebRequest with POST or PUT
PowerShell scripts referencing Invoke-WebRequest with -Method POST/PUT indicate potential data upload behavior.
frack113, Huntrule TeamWindowsps_scriptLow215Free2022-01-07PowerShell DNSExfiltrator command usage (DNSExfiltration)
Detects PowerShell use of Invoke-DNSExfiltrator for DNS/DoH-based exfiltration based on Script Block Logging content.
frack113, Huntrule TeamWindowsps_scriptHigh131Free2022-01-07Windows PowerShell: Invoke-Command targeting -ComputerName via script block
Detects PowerShell Invoke-Command targeting remote hosts by matching script block text with -ComputerName.
frack113, Huntrule TeamWindowsps_scriptMedium152Free2022-01-07Windows PowerShell script enabling WinRM via Enable-PSRemoting
Alerts on PowerShell scripts that include Enable-PSRemoting, a common step to activate WinRM for remote access.
frack113, Huntrule TeamWindowsps_scriptMedium91Free2022-01-07Windows Suspicious Outbound SMTP Connections on Common Mail Ports
Alerts on outbound, initiated SMTP connections to ports 25/465/587/2525, excluding specific mail/Exchange processes.
frack113, Huntrule TeamWindowsnetwork_connectionMedium153Free2022-01-07Windows Registry: Detect windir Environment Key Changes for SilentCleanup UAC Bypass
Detects non-default Environment\windir registry changes commonly used to facilitate SilentCleanup UAC bypass.
frack113, Nextron Systems, Huntrule TeamWindowsregistry_setHigh3110Free2022-01-06