Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,393 rules
Windows: Detect UAC bypass attempts via winsat.exe path parsing from user temp
Flags file activity targeting Temp\system32\winsat.exe (or winmm.dll) under C:\Users\ consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh112Free2021-08-30Windows UAC bypass using NTFS reparse point to place a hijack DLL in Temp
Alerts on file events pointing to a Temp legacy kernel32 DLL within user AppData, consistent with UAC bypass via reparse/DLL targeting.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh267Free2021-08-30Windows UAC Bypass via msconfig Token Modification Dropping pkgmgr.exe from Temp
Alerts on writes to C:\Users\…\AppData\Local\Temp\pkgmgr.exe indicative of msconfig-based UAC bypass staging.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh71Free2021-08-30Windows UAC bypass via IEInstal.exe dropping consent.exe to Temp
Alerts on IEInstal.exe activity writing consent.exe under AppData Local Temp to support a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh372Free2021-08-30Windows UAC Bypass via .NET Code Profiler DLL Hijacking on mmc.exe (pe386.dll in Temp)
Flags creation of Temp\pe386.dll under a user profile, consistent with mmc/.NET code profiler UAC bypass behavior.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh141Free2021-08-30Windows Process Creation Matching TrustedPath UAC Bypass Directory Mocking Strings
Alerts on Windows processes referencing System32/SysWOW64 paths consistent with TrustedPath UAC bypass directory mocking.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical132Free2021-08-27Exchange Management: Removal of Mailbox Export Request via Remove-MailboxExportRequest
Detects Exchange management removals of mailbox export requests using Remove-MailboxExportRequest with Confirm set to "False".
Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh81Free2021-08-27Windows Security: Suspicious Registry Access to ADHealthAgent Health Service Agent Keys
Detects non-standard processes accessing HKLM\SOFTWARE\Microsoft\ADHealthAgent registry key activity in Windows security logs.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamWindowssecurityMedium60Free2021-08-26Windows Security: Access to Azure AD Health Monitoring Agent Registry Key
Flags suspicious access to the Azure AD Health Monitoring Agent registry key using Windows Security 4656/4663.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamWindowssecurityMedium60Free2021-08-26Windows Registry UAC Bypass Attempt via Windows Media Player osk.exe AppCompatFlags
Identifies registry AppCompatFlags entries for Windows Media Player osk.exe that may indicate a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2021-08-23Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-23Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.
Vadim Khrykov, Cyb3rEng, Huntrule TeamWindowsprocess_creationHigh162Free2021-08-23Windows UAC bypass using wsreset.exe with high/SYSTEM integrity
Alerts when wsreset.exe is executed with elevated integrity (High or SYSTEM), indicating a potential UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2021-08-23Windows Process UAC Bypass via Windows Media Player osksupport.dll (osk.exe → cmd.exe)
Alerts on osk.exe spawning cmd.exe under mmc event viewer with high/system integrity, consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh325Free2021-08-23Windows UAC Bypass via pkgmgr.exe Launching dism.exe (High/System Integrity)
Detects pkgmgr.exe spawning dism.exe with High/System integrity levels on Windows, a pattern used in UAC bypass attempts.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh428Free2021-08-23