Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,402 rules
Windows PowerShell Script: Remove Account From Domain Admin Group via Remove-ADGroupMember
Alerts on PowerShell commands removing specified members via Remove-ADGroupMember, potentially disrupting Domain Admin access.
frack113, Huntrule TeamWindowsps_scriptMedium151Free2021-12-26Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh70Free2021-12-22Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Alerts on Windows process executions using filenames that match common Sysinternals tools to indicate potential binary impersonation.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2021-12-20Suspicious Windows Process Creation as SYSTEM User with Likely Credential/Defense Evasion Commands
Flags SYSTEM-context process executions on Windows that include suspicious tool names or command-line patterns such as PowerShell/Mimikatz indicators.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindowsprocess_creationHigh132Free2021-12-20Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Flags reg.exe or PowerShell registry edits that alter the ms-settings protocol handler open command path.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium288Free2021-12-20Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo
Alerts on sqlcmd.exe running a query targeting the VeeamBackup dbo Credentials table to dump sensitive credentials.
frack113, Huntrule TeamWindowsprocess_creationHigh343Free2021-12-20Windows: Detect sc.exe Service Creation with DACL Modification (sdset DCLCWPDTSD)
Alerts on sc.exe sdset usage with DCLCWPDTSD, suggesting permission changes to hide or impede service removal.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh60Free2021-12-20Windows reg.exe Credential Enumeration via Registry Query (HKLM/HKCU)
Flags reg.exe registry queries (REG_SZ, recursive) focused on HKLM/HKCU and PuTTY Sessions to enumerate credential material.
frack113, Huntrule TeamWindowsprocess_creationMedium2010Free2021-12-20PowerShell Credential Manager enumeration via vaultcmd /listcreds
Flags PowerShell using vaultcmd /listcreds to enumerate Windows/Web credential manager stored entries.
frack113, Huntrule TeamWindowsps_scriptMedium133Free2021-12-20PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)
Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.
frack113, Huntrule TeamWindowsps_scriptMedium4310Free2021-12-20PowerShell Credential Discovery via Recursive File Search and Select-String
Flags PowerShell script blocks that recursively list files and run select-string pattern searches, indicative of credential hunting.
frack113, Huntrule TeamWindowsps_scriptMedium144Free2021-12-19Windows: Process Execution of PsLogList with Event Log Dump/Export Flags
Detects PsLogList executions aimed at Security/Application/System logs with dump/export/clear command-line switches.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2021-12-18Windows CleanWipe-Like PUA Execution via System Tool Uninstall Switches
Flags Windows processes launching CleanWipe-like removal tools with uninstall parameters for security impairment investigation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh229Free2021-12-18Windows Process Creation: Advanced Port Scanner PUA Execution via /portable /lng
Flags Windows launches of Advanced Port Scanner with /portable and /lng parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2021-12-18Windows Process Command-Line Flags Indicating Auditpol Policy Tampering
Detects auditpol runs with flags that disable key audit categories, indicating potential audit policy tampering for defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-12-18