Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,404 rules
Potential DLL Injection via AccCheckConsole.exe Command-Line Parameters on Windows
Alerts on AccCheckConsole.exe executions whose CLI parameters align with loading custom verification logic via a DLL.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-01-06Windows PowerShell Remote Session Creation via New-PSSession
Flags PowerShell usage of New-PSSession with a ComputerName in script block logging, indicating remote session creation.
frack113, Huntrule TeamWindowsps_scriptMedium172Free2022-01-06Windows Registry: Disable User Account Control by setting EnableLUA to 0
Alerts on Windows registry changes that disable UAC by writing EnableLUA as 0.
frack113, Huntrule TeamWindowsregistry_setMedium141Free2022-01-05Registry Modification for UAC Bypass via Event Viewer Command Handler (Windows)
Monitors registry value changes to the Event Viewer command handler path indicative of a UAC bypass attempt on Windows.
frack113, Huntrule TeamWindowsregistry_setHigh133Free2022-01-05Windows Registry: Detect DelegateExecute UAC bypass via TargetObject path
Alerts on registry set events targeting \open\command\DelegateExecute with empty Details, consistent with a UAC bypass attempt.
frack113, Huntrule TeamWindowsregistry_setHigh4310Free2022-01-05Windows Process Creation: Pypykatz Credential Dumping via Registry Parsing
Alerts when pypykatz is run with "live" and "registry" parameters to extract credential data from local SAM-related artifacts.
frack113, Huntrule TeamWindowsprocess_creationHigh391Free2022-01-05Windows WinRAR Compression of .dmp/.dump Files via Command Line
Flags WinRAR executions on Windows whose command lines reference .dmp/.dump/.hdmp extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium337Free2022-01-04Windows: Uncommon format.com File System Load via /fs parameter
Alerts on format.com executions with atypical /fs: parameters, which may indicate defense-evasion use of Windows utilities.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-01-04Windows Process Creation: createdump.exe Dumping Memory with Full and Name Flags
Flags and .dmp output usage indicate createdump.exe dumping process memory on Windows.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh278Free2022-01-04Windows Process Creation: Headless Chromium Download via dump-dom
Flags headless Chromium browser executions using dump-dom and an http URL on Windows, indicative of stealthy remote content retrieval.
Sreeman, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-01-04Windows Process Creation: cscript/wscript Running gatherNetworkInfo.vbs
Alerts on cscript/wscript processes running gatherNetworkInfo.vbs, indicating potential host/network reconnaissance.
blueteamer8699, Huntrule TeamWindowsprocess_creationMedium131Free2022-01-03Suspicious PowerShell Execution with Base64 Encoded Command (Windows)
Alerts on PowerShell launched with Base64-encoded command-line parameters, excluding likely Guest Configuration noise.
frack113, Huntrule TeamWindowsprocess_creationMedium123Free2022-01-02Windows PowerShell Starts Process Using Batch (.cmd/.bat) Scripts
Flags PowerShell Start-Process activity that references .bat/.cmd files, indicating batch script execution attempts.
frack113, Huntrule TeamWindowsps_scriptMedium122Free2022-01-02Windows Backup File Deletion Triggered by CLI or Script Hosts
Alerts when cmd.exe, PowerShell, wt.exe, rundll32.exe, or regsvr32.exe delete files with backup-oriented filename extensions.
frack113, Huntrule TeamWindowsfile_deleteMedium121Free2022-01-02Windows Registry: RDP PortNumber changed from default 3389
Alerts on Windows registry updates to the RDP-Tcp PortNumber when it changes away from default 3389.
frack113, Huntrule TeamWindowsregistry_setHigh142Free2022-01-01