Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,395 rules
PowerShell Creating Startup .lnk Shortcut Persistence (Windows File Events)
Detects PowerShell writing .lnk files into the Windows Startup folder, a common persistence mechanism.
Christopher Peacock '@securepeacock', SCYTHE, Huntrule TeamWindowsfile_eventHigh1910Free2021-10-24Windows: CertOC.exe certificate utility loading a DLL via -LoadDLL
Flags CertOC.exe launching with -LoadDLL to load a specified DLL on Windows.
Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium60Free2021-10-23Windows Process Execution via WorkFolders.exe Launching control.exe
Alerts when WorkFolders.exe spawns a non-standard control.exe instance on Windows.
Maxime Thiebaut (@0xThiebaut), Huntrule TeamWindowsprocess_creationHigh113Free2021-10-21Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
Detects stordiag.exe spawning schtasks.exe, systeminfo.exe, or fltmc.exe to support system discovery or config actions on Windows.
Austin Songer (@austinsonger), Huntrule TeamWindowsprocess_creationHigh142Free2021-10-21PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Flags PowerShell script block text indicating WindowStyle set to Hidden, suggesting concealed execution.
frack113, Tim Shelton (fp AWS), Huntrule TeamWindowsps_scriptMedium235Free2021-10-20PowerShell: Set-ExecutionPolicy to Unrestricted or Bypass
Alerts when PowerShell sets execution policy to Unrestricted or bypass, indicating weakened script execution controls.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2021-10-20Windows Registry: Clearing RDP Client Connection History via MRU and Server Keys Deletion
Flags registry deletions that remove Windows RDP client connection history from Terminal Server Client MRU and Servers keys.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh457Free2021-10-19Windows PowerShell: Disable Windows Firewall Profile via Set-NetFirewallProfile
Flags PowerShell commands that disable one or more Windows Firewall profiles via Set-NetFirewallProfile -Enabled $false.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptMedium132Free2021-10-12Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
bohops, Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh153Free2021-10-08Windows Named Pipe Access to ADFS/WID Database by Uncommon Process
Alert on named pipe creation to the AD FS WID SQL query endpoint when initiated by uncommon processes.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowspipe_createdMedium122Free2021-10-08Windows: Suspicious Driver Installation via pnputil.exe
Flags pnputil.exe command lines indicating driver install/add actions targeting .inf files on Windows.
Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium135Free2021-09-30Windows DataSvcUtil.exe Command-Line Exfiltration Using /in:, /out:, and /uri:
Alerts on DataSvcUtil.exe runs with /in:, /out:, and /uri: parameters that may indicate data exfiltration activity.
Ialle Teixeira @teixeira0xfffff, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium101Free2021-09-30Windows Prefetch File Deletion via .pf File Removal
Flags deletion of .pf files in \\Windows\\Prefetch, a possible attempt to remove execution artifacts.
Cedric MAURUGEON, Huntrule TeamWindowsfile_deleteHigh174Free2021-09-29Windows Process Memory Dump Using RdrLeakDiag.exe (/memdmp|fullmemdmp)
Alerts on Windows executions of rdrleakdiag.exe that request full or targeted memory dumps via /memdmp or /fullmemdmp.
Cedric MAURUGEON, Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4610Free2021-09-24PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsps_scriptHigh163Free2021-09-21