Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,392 rules
Windows UAC bypass via changepk.exe launched from slui.exe with elevated integrity
Flags changepk.exe execution from slui.exe with High/System integrity to identify potential UAC bypass behavior on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-08-23Windows Process Creation: Suspicious splwow64.exe Missing Command-Line Parameters
Flags Windows executions of splwow64.exe where the command line ends at the executable with no parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2021-08-23Windows UAC Bypass via WoW64 Logger DLL Hijack (Process Access Pattern)
Flags SysWOW64 process-access behavior with high granted access and unknown call traces consistent with a WoW64 logger DLL hijack UAC bypass.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh112Free2021-08-23PowerShell discovery of Win32_PnPEntity via ScriptBlockText
Alerts when PowerShell script blocks reference Win32_PnPEntity to enumerate attached Plug and Play devices.
frack113, Huntrule TeamWindowsps_scriptLow373Free2021-08-23Windows Named Pipe Creation Matching EfsPotato-Style \\pipe\\srvsvc
Alerts on Windows named pipe creation events matching an EfsPotato-style PipeName pattern (\pipe\ and \pipe\srvsvc), excluding common benign contexts.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdHigh151Free2021-08-23UAC Bypass via Windows Media Player: DllHost.exe spawning osk.exe writing OskSupport.dll to Temp
Flags file events where Temp\OskSupport.dll is targeted alongside DllHost.exe and Windows Media Player\osk.exe, consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh92Free2021-08-23Windows UAC Bypass via consent.exe with comctl32.dll file path pattern
Detects suspicious target path patterns involving consent.exe.@ and comctl32.dll consistent with UAC bypass staging.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh173Free2021-08-23Windows Office Applications Creating Executable/Script Files with Suspicious Extensions
Flags Office application processes creating .exe/.dll/.ps1 and other script or executable files on Windows.
Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh367Free2021-08-23Exchange Management: Certificate CSR exported to webserver or .aspx-named path
Flags Exchange CSR export commands that write request files to C$ and web-root paths or use an .aspx filename.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical152Free2021-08-23PowerShell Write-Hijack HackTool Creates .bat for DLL Hijack Execution (Windows)
Flags PowerShell creating .bat files consistent with PowerUp Write-Hijack DLL abuse on Windows.
Subhash Popuri (@pbssubhash), Huntrule TeamWindowsfile_eventHigh101Free2021-08-21Windows: Detect reg.exe Changing Screen Saver Registry Settings for .scr Payloads
Flags reg.exe command lines that modify HKCU desktop screensaver settings and configure a .scr screen saver payload.
frack113, Huntrule TeamWindowsprocess_creationMedium141Free2021-08-19PowerShell WMI Event Subscription Persistence via New-CimInstance
Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.
frack113, Huntrule TeamWindowsps_scriptMedium383Free2021-08-19Windows PowerShell: Add-Content to $profile for Potential Persistence
Detects PowerShell Add-Content writing to $profile, especially when paired with common command-loading or execution payloads.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium153Free2021-08-18Windows Procdump Process Execution
Alerts on execution of Sysinternals Procdump (32/64 variants) based on process creation image path.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium482Free2021-08-16Windows whoami.exe Execution from Suspicious Parent Processes
Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2021-08-12