Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,399 rules
PowerShell Security Software Discovery Using get-process Piped to where-object (Windows)
Flags PowerShell scripts that enumerate processes and filter results for security software by vendor/product keywords.
frack113, Anish Bogati, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium161Free2021-12-16Windows PowerShell: Query SMB Shares via Get-SmbShare
Alerts on PowerShell script blocks running Get-SmbShare to discover SMB shares.
frack113, Huntrule TeamWindowsps_scriptLow103Free2021-12-15PowerShell ScriptBlock Enumeration of AD Group Membership and User Attributes (Windows)
Flags PowerShell script blocks querying AD group membership and user details for discovery of privileged directory information.
frack113, Huntrule TeamWindowsps_scriptLow351Free2021-12-15PowerShell Module: Get-SmbShare Used for SMB Share Discovery
Detects PowerShell module usage of Get-SmbShare to enumerate SMB shares across networked systems.
frack113, Huntrule TeamWindowsps_moduleLow465Free2021-12-15PowerShell module enumeration of AD principals via get-ADPrincipalGroupMembership
Flags PowerShell module usage of Get-ADPrincipalGroupMembership and Get-ADUser with -pr -f patterns indicative of AD discovery.
frack113, Huntrule TeamWindowsps_moduleLow234Free2021-12-15Windows process execution of where.exe with browser bookmark database or history artifacts
Alerts on where.exe executions referencing browser history/bookmarks/cookie database artifacts in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow132Free2021-12-13Windows: Delete Backup or System State Backups via wbadmin.exe
Flags wbadmin.exe command lines that delete backup or system state backups, potentially impacting recovery.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium141Free2021-12-13Windows wbadmin.exe Deletes All Backup Copies (keepVersions:0)
Flags wbadmin.exe executions that delete all backups/system state backups using keepVersions:0.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-12-13Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
frack113, Huntrule TeamWindowsprocess_creationHigh245Free2021-12-13Windows CMD dir /S File and Subfolder Enumeration
Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.
frack113, Huntrule TeamWindowsprocess_creationLow121Free2021-12-13PowerShell Script Block Collection of Browser Bookmarks via Get-ChildItem
Detects PowerShell Get-ChildItem activity used to recursively enumerate browser bookmarks from a target path.
frack113, Huntrule TeamWindowsps_scriptLow182Free2021-12-13Windows Process Discovery via wmic.exe "group" Flag
Flags wmic.exe process executions querying local group information via a "group" command-line argument.
frack113, Huntrule TeamWindowsprocess_creationLow298Free2021-12-12PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
frack113, Huntrule TeamWindowsps_scriptLow319Free2021-12-12PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
frack113, Huntrule TeamWindowsps_moduleLow111Free2021-12-12Windows Process Creation: Nmap/Zenmap (nmap.exe or zennmap.exe) Execution
Flags Windows execution of Nmap/Zenmap (nmap.exe or zennmap.exe) used for remote service discovery.
frack113, Huntrule TeamWindowsprocess_creationMedium171Free2021-12-10