Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,395 rules
Windows AD CS Certificate Template Updated/Created Enrollee Supplies Subject Flag
Alerts when AD CS certificate templates are created or updated with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT.
Orlinum , BlueDefenZer, Huntrule TeamWindowssecurityLow191Free2021-11-17Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Alerts on scheduled task storage writes under System32\Tasks originating from suspicious process locations.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh141Free2021-11-16Windows: reg.exe Adds BitLocker Policy Registry Values
Flags reg.exe registry additions targeting BitLocker policy keys associated with configuration changes.
frack113, Huntrule TeamWindowsprocess_creationHigh396Free2021-11-15Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh257Free2021-11-15Windows Office Apps Initiate Outbound Network Connections to Non-Private IPs
Alerts when Office app processes initiate outbound TCP/HTTP(S)/mail connections to non-private IPs, excluding common private and known provider ranges.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium384Free2021-11-10Suspicious DNS Query Patterns for Cobalt Strike Beacons on Windows (Sysmon)
Alerts on Windows Sysmon DNS queries with QueryName patterns consistent with Cobalt Strike DNS beaconing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryCritical173Free2021-11-09Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Alerts on Windows file creation events for Mimikatz-related .kirbi and mimilsa.log files.
Florian Roth (Nextron Systems), David ANDRE, Huntrule TeamWindowsfile_eventCritical101Free2021-11-08Windows ZipExec-Style Suspicious PowerShell/Command Execution with Password-Protected ZIP
Flags Windows processes running ZipFolder zip commands with password and .zip filename parameters, optionally including deletion.
frack113, Huntrule TeamWindowsprocess_creationMedium162Free2021-11-07Windows Process Creation: cscript/wscript Register-App.vbs COM+ Registration
Alert on cscript/wscript running “.vbs -register” to register COM+ components, potentially leveraging register_app.vbs.
Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium269Free2021-11-05Windows: Cmdl32.EXE Arbitrary File Download Indicator via /vpn and /lan Flags
Flags cmdl32.exe executions using /vpn and /lan that may indicate arbitrary file retrieval behavior.
frack113, Huntrule TeamWindowsprocess_creationMedium93Free2021-11-03Windows Process Creation: PowerShell ExecutionPolicy Set to Bypass/Unrestricted
Alerts on PowerShell started with -ExecutionPolicy set to Bypass/Unrestricted, indicating a potentially insecure script execution posture.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2021-11-01Windows Process Creation: Command-Line Indicators of Crypto Mining
Alerts on Windows processes with command-line arguments matching common crypto miner pool and configuration indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2021-10-26Windows Process Creation: Suspicious Command-Line Path Traversal Evasion Strings
Flags Windows command-line strings that look like “..\” path traversal evasion attempts, excluding known Google Drive and Citrix launcher patterns.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium346Free2021-10-26Windows Network Connections to Known Crypto Mining Pools
Flags Windows hosts making outbound connections to known cryptocurrency mining pool domains.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh398Free2021-10-26Windows Browser Process Creating VHD/VHDX Files via Download
Alerts when a Windows browser process creates files containing .vhd, indicating potential VHD/VHDX staging.
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsfile_eventMedium92Free2021-10-25