Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,398 rules
Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Alerts when SharpView.exe runs with command-line indicators of AD and network discovery/enumeration activity.
frack113, Huntrule TeamWindowsprocess_creationHigh192Free2021-12-10PowerShell Get-NetTCPConnection Network Connection Discovery (Windows)
Detects PowerShell use of Get-NetTCPConnection to enumerate TCP network connections for discovery.
frack113, Huntrule TeamWindowsps_moduleLow131Free2021-12-10Windows PowerShell: Query TCP connections with Get-NetTCPConnection
Detects PowerShell usage of Get-NetTCPConnection to enumerate TCP network connections.
frack113, Huntrule TeamWindowsps_classic_startLow402Free2021-12-10Windows Process Creation: Suspicious Executable Image Extension
Flags Windows process creations where the executable image path ends with an unexpected extension, after filtering known benign cases.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium308Free2021-12-09Windows Process Creation: Executable Image Missing Absolute Path (Possible Process Ghosting)
Flags Windows process creation where the executable Image lacks an absolute path, potentially indicating process ghosting.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh331Free2021-12-09Windows Process Creation: Suspicious Network Configuration and Discovery Commands
Alerts on Windows command-line usage of network configuration and discovery tools (ipconfig, netsh, arp, nbtstat, net config, route print).
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow203Free2021-12-07Windows netsh.exe Firewall Configuration Discovery (show firewall rule/state/name=all)
Flags netsh.exe commands used to enumerate Windows firewall rules and states via “show firewall … name=all”.
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow186Free2021-12-07Windows PowerShell Process Creation with DInjector Cradle Flags (/am51 and /password)
Identifies Dinject PowerShell cradle usage by matching command-line flags '/am51' and '/password' in Windows process creation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical4810Free2021-12-07Windows: Suspicious PowerShell Interactive History Files Created as SYSTEM
Alerts on creation of PowerShell interactive history/profile files under SYSTEM, signaling privileged PowerShell activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh124Free2021-12-07Windows: User Added to Local Remote Desktop Users Group via Net or PowerShell
Detects Windows command-line activity that adds a user to the local Remote Desktop Users group using net localgroup or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh312Free2021-12-06Windows: Network connections initiated to api.mega.co.nz or mega.nz
Identifies initiated Windows outbound connections to api.mega.co.nz/mega.nz for potential file-transfer staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionLow227Free2021-12-06Windows: Remote Network Share Writes to desktop.ini
Flags remote network-shared desktop.ini being written to with high-impact permissions in Windows Security logs.
Tim Shelton (HAWK.IO), Huntrule TeamWindowssecurityMedium3510Free2021-12-06Windows System Logs: Windows Update Client errors (connection, install, uninstall, revert, commit)
Alerts on Windows Update Client errors in System logs, including connection, install, uninstall, revert, and commit failures.
frack113, Huntrule TeamWindowssystemInformational198Free2021-12-04Windows Process Command Line Containing Whoami as First Parameter
Flags Windows process creations with command lines containing '.exe whoami' to surface potential discovery behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-11-29Windows Regsvr32.exe Executed with Suspicious File Extension Masquerading as DLL
Alerts when REGSVR32.exe runs with a command-line argument ending in a suspicious masquerade file extension.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh161Free2021-11-29