Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,397 rules
Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
Florian Roth (Nextron Systems), Samir Bousseaden, Huntrule TeamWindowsprocess_creationCritical382Free2021-11-27Windows extrac32.exe CAB extraction via Alternate Data Stream execution
Flags Windows executions of extrac32.exe that target a .cab and include an alternate data stream path indicator.
frack113, Huntrule TeamWindowsprocess_creationMedium143Free2021-11-26Windows Diantz.exe Command-Line ADS CAB Creation
Flags Diantz commands that create or reference a .cab using an Alternate Data Stream (ADS) pattern on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium286Free2021-11-26Windows Process Creation: Dump64.EXE Renamed into Visual Studio Folder
Alerts on Visual Studio–staged dump64.exe masquerading, potentially indicating an attempt to bypass Windows Defender AV.
Austin Songer @austinsonger, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2021-11-26Windows ConfigSecurityPolicy.EXE Used for HTTP/FTP Arbitrary File Transfers
Alert when ConfigSecurityPolicy.exe runs with ftp/http/https URLs in the command line, indicating potential file transfer abuse.
frack113, Huntrule TeamWindowsprocess_creationMedium133Free2021-11-26Windows PowerShell Clears Console History via Clear-History
Flags PowerShell attempts to clear or delete console/PSReadline command history to hinder command forensics.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptHigh60Free2021-11-25Windows: Rundll32 Loading shell32.dll via Control_RunDLL from User/Temp Paths
Alerts on rundll32.exe loading shell32.dll with Control_RunDLL from AppData/Temp/user paths.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2021-11-24Windows CertReq -Post Download Attempt via HTTP
Flags certreq.exe executions using -Post -config and HTTP content retrieval indicators.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh359Free2021-11-24Windows bash.exe Launched with -c for Indirect Inline Command Execution
Alerts on Windows processes starting bash.exe with -c, indicating inline command execution.
frack113, Huntrule TeamWindowsprocess_creationMedium421Free2021-11-24Windows: aspnet_compiler.exe Execution Detection
Detects execution of aspnet_compiler.exe from Windows .NET Framework directories, which can be abused to compile and run C#.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2021-11-24Windows DNS Queries Triggered by DesktopAppInstaller AppInstaller.EXE
Identifies DNS lookups performed by Windows AppInstaller.EXE when initiating ms-appinstaller package installation from a URL.
frack113, Huntrule TeamWindowsdns_queryMedium335Free2021-11-24Windows PsExec/PAExec Command-Line Flags Escalating to LOCAL SYSTEM
Flags in PsExec/PAExec command lines requesting LOCAL SYSTEM execution are matched via process creation command-line telemetry.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2021-11-23Windows process access to LSASS.exe with suspicious GrantedAccess flags
Alerts on process access attempts to lsass.exe with GrantedAccess rights commonly linked to credential theft behavior.
Florian Roth, Roberto Rodriguez, Dimitrios Slamaris, Mark Russinovich, Thomas Patzke, Teymur Kheirkhabarov, Sherif Eldeeb, James Dickenson, Aleksey Potapov, oscd.community, Huntrule TeamWindowsprocess_accessMedium402Free2021-11-22Windows Shell/Scripting Tool File Write to Suspicious Directories
Alert on file writes by common Windows shells/scripting tools to C:\PerfLogs, C:\Users\Public, or C:\Windows\Temp.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh153Free2021-11-20Windows Registry New File Association via exefile Handler (Classes\*.exefile)
Alerts on Windows registry changes creating a new file association that points to the exefile handler.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_setHigh103Free2021-11-19