Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,392 rules
Windows whoami.exe Renamed Execution via Mismatched OriginalFileName
Alerts when a renamed process still reports OriginalFileName as whoami.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical90Free2021-08-12Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Flags winword.exe process injection where the call trace matches LittleCorporal-generated Maldoc activity on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh152Free2021-08-09PowerShell ShellIntel Commandlet Abuse via ScriptBlock Logging
Flags PowerShell script blocks that reference known ShellIntel commandlets tied to exploitation activity.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsps_scriptHigh141Free2021-08-09Microsoft Exchange: Mailbox export to UNC path or .aspx filename with possible role assignment
Flags Exchange mailbox export commands targeting UNC paths with .aspx or granting the Mailbox Import Export role.
Florian Roth (Nextron Systems), Rich Warren, Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical284Free2021-08-09Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation
Flags Exchange management command lines invoking Set-OabVirtualDirectory with suspicious external URL/script injection patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical4010Free2021-08-09Windows AnyDesk Silent Installation via Command-Line Flags
Identifies AnyDesk being silently installed on Windows using --install, --start-with-win, and --silent command-line flags.
Ján Trenčanský, Huntrule TeamWindowsprocess_creationHigh203Free2021-08-06Windows esentutl Usage with /p Flag for Credential Access
Flags Windows executions of esentutl when used with the /p parameter to access credentials-related files.
sam0x90, Huntrule TeamWindowsprocess_creationMedium132Free2021-08-06Windows Registry: Tamper Protection Disabled in Microsoft Defender Features
Flags registry changes that set Microsoft Defender Tamper Protection to disabled (DWORD 0x0), excluding expected MsMpEng update activity.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium3510Free2021-08-04Windows Registry: Disabling Windows Defender PUA Protection via PUAProtection DWORD
Flags registry changes that set Windows Defender PUAProtection DWORD to 0x00000000 to disable PUA protection.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setHigh256Free2021-08-04Windows Registry: Disable Windows Defender Exploit Guard Network Protection via Policy Override
Alerts on registry policy changes that override Exploit Guard Network Protection settings for Windows Defender.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium161Free2021-08-04Windows process access matching Cobalt Strike BOF injection call trace
Flags suspicious Windows process access consistent with CobaltStrike BOF injection using ntdll/KERNELBASE call traces and high GrantedAccess.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh183Free2021-08-04PowerShell timestomping via file timestamp property and setter usage (Windows)
Identifies PowerShell timestomping attempts by matching script text that sets file creation, access, and write timestamps.
frack113, Huntrule TeamWindowsps_scriptMedium212Free2021-08-03PowerShell Virtualization Environment Discovery via WMI in ScriptBlockLogging (Windows)
Identifies PowerShell WMI queries for Win32 computer system and ACPI thermal data used to check virtualization environments.
frack113, Duc.Le-GTSC, Huntrule TeamWindowsps_scriptMedium354Free2021-08-03Windows Process Creation: ADCSPwn Command-Line Parameters Indicating ADCS Abuse
Identifies Windows processes with command-line arguments consistent with ADCSPwn targeting ADCS and a specified port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh479Free2021-07-31Windows Process Creation: Recon Data Export via Command Prompt Redirection
Alerts when recon-related Windows utilities are launched with command-line output redirected to temp locations.
frack113, Huntrule TeamWindowsprocess_creationMedium133Free2021-07-30