Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,394 rules
PowerShell Add-DnsClientNrptRule Modifies NRPT Namespaces
Flags PowerShell scripts that add DNS Name Resolution Policy Table rules for a specified namespace.
Borna Talebi, Huntrule TeamWindowsps_scriptHigh192Free2021-09-14PowerShell ScriptBlock launching redirected comspec to Alternate Data Stream via '>'
Flags PowerShell script blocks using Start-Process with comspec and " > " redirection consistent with ADS-style file hiding.
frack113, Huntrule TeamWindowsps_scriptMedium93Free2021-09-02Windows Kerberos TGT Request with AD CS Certificate Thumbprint Anomalies (EventID 4768)
Identifies unusual certificate-associated Kerberos TGT (4768) requests targeting computer accounts on Windows.
Mauricio Velazco, Michael Haag, Huntrule TeamWindowssecurityHigh82Free2021-09-02Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowswmi_eventHigh364Free2021-09-01Windows Process Creation: Execution CommandLines Involving NTFS Alternate Data Streams
Alerts on Windows executions whose command lines reference NTFS Alternate Data Streams combined with specific file-data tools.
frack113, Huntrule TeamWindowsprocess_creationMedium2310Free2021-09-01Windows WMI Event Consumer (scrcons.exe) Creates Named Pipe
Flags scrcons.exe creating a Windows named pipe, using named pipe creation event telemetry.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdMedium187Free2021-09-01Windows Atera RMM Agent Installation via MsiInstaller Event ID 1033
Flags Windows MSI installs where installer logs indicate an AteraAgent installation (EventID 1033, MsiInstaller).
Bhabesh Raj, Huntrule TeamWindowsapplicationHigh122Free2021-09-01Windows UAC Bypass via ComputerDefaults.exe with Elevated Integrity Parent Process
Flags ComputerDefaults.exe runs at high/system integrity when the parent isn’t from typical system or Program Files paths.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2021-08-31Windows Registry UAC Bypass via winsat.exe LowerCaseLongPath and UACMe Path Parsing
Matches registry writes that reference winsat.exe using a LowerCaseLongPath construction consistent with UAC bypass path parsing.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh179Free2021-08-30Windows Process Creation: UAC Bypass via winsat.exe Path Parsing
Alerts on elevated processes spawned by Temp-path winsat.exe with system32 winsat command-line content.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh444Free2021-08-30Windows UAC Bypass via NTFS Reparse Point: wusa.exe DLL Hijacking Process Behavior
Alerts on high-integrity wusa.exe launched from Temp update.msu with a dism.exe parent showing DismHost activity.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2021-08-30Windows UAC Bypass via msconfig Token Modification (msconfig.exe -5) Process Creation
Flags msconfig.exe invoked with -5 from a Temp pkgmgr.exe parent under elevated integrity levels, indicating a possible UAC bypass.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-08-30Windows UAC Bypass via IEInstal.exe Launching consent.exe from Temp with Elevated Integrity
Alerts on elevated consent.exe spawned by ieinstal.exe from Temp, indicating a possible Windows UAC bypass chain.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2021-08-30Windows UAC Bypass via DismHost.exe DLL Hijacking
Flags DismHost.exe executions from AppData\Local\Temp running as High/System integrity, consistent with UAC bypass via DLL hijacking.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-30Windows UAC Bypass via Disk Cleanup cleanmgr.exe run from Scheduled Task
Flags scheduled-task executions of cleanmgr.exe with disk-cleanup parameters running at high/System integrity.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh159Free2021-08-30