Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,359 rules
Windows: InfDefaultInstall.exe .inf Execution
Flags Windows process executions of InfDefaultInstall.exe that include an .inf argument in the command line.
frack113, Huntrule TeamWindowsprocess_creationMedium181Free2021-07-13Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleHigh527Free2021-07-13Windows PowerShell ModuleContents Set to Get-VMRemoteFXPhysicalVideoAdapter
Alerts on PowerShell module creation embedding Get-VMRemoteFXPhysicalVideoAdapter, a potential precursor to RemoteFXvGPUDisablement.exe abuse.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspowershell-classicHigh452Free2021-07-13Windows Uninstall CrowdStrike Falcon Sensor via WindowsSensor.exe /uninstall /quiet
Flags Windows processes uninstalling CrowdStrike Falcon Sensor using WindowsSensor.exe with /uninstall and /quiet.
frack113, Huntrule TeamWindowsprocess_creationHigh203Free2021-07-12Windows Process: SyncAppvPublishingServer.exe Executes PowerShell via PowerShell-encoded command
Alerts when SyncAppvPublishingServer.exe is launched with a command-line pattern indicative of PowerShell code execution.
frack113, Huntrule TeamWindowsprocess_creationMedium226Free2021-07-12Windows Process Injection via Mavinject Using INJECTRUNNING Flag
Alerts on Windows process creation using Mavinject with /INJECTRUNNING, indicative of DLL injection into a running process.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh307Free2021-07-12Windows spoolsv.exe Child Process Execution Indicators
Flags suspicious process executions where spoolsv.exe (print spooler) spawns utility, scripting, or rundll32 children with high integrity.
Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule), Huntrule TeamWindowsprocess_creationHigh191Free2021-07-11Windows DNS Queries for IP Lookup Service Domains from Non-Browser Processes
Flags suspicious DNS lookups to IP-check API domains on Windows when they come from non-browser executables.
Brandon George (blog post), Thomas Patzke, Huntrule TeamWindowsdns_queryMedium213Free2021-07-08Windows Process Creation: MpCmdRun.exe Removing All Windows Defender Definitions
Flags MpCmdRun.exe launched to remove all Windows Defender definition files.
frack113, Huntrule TeamWindowsprocess_creationHigh181Free2021-07-07Windows Registry Defender Exclusions Path Set (Microsoft\Windows Defender\Exclusions)
Identifies registry updates that reference the Windows Defender Exclusions path, indicating potential defense impairment.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setMedium497Free2021-07-06Windows Defender Exclusions Added via Windefend (Event ID 5007)
Alerts on Windows Defender exclusion additions based on windefend Event ID 5007 configuration change events.
Christian Burkard (Nextron Systems), Huntrule TeamWindowswindefendMedium243Free2021-07-06Windows windefend: Detect Tamper Protection blocks changes to Microsoft Defender settings
Flags Defender tamper protection blocks to disable key Microsoft Defender Antivirus and real-time protection settings.
Bhabesh Raj, Nasreddine Bencherchali, Huntrule TeamWindowswindefendHigh211Free2021-07-05Windows SMB Client Security: Rejected Guest Logon with Blank UserName
Flags rejected SMB guest/anonymous-style logons on Windows when the SMB username is blank.
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Huntrule TeamWindowssmbclient-securityMedium248Free2021-06-30Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
Wojciech Lesicki, Huntrule TeamWindowsregistry_setHigh233Free2021-06-29Windows reg.exe Run Key Modification for Persistence via Process Creation
Alerts on reg.exe commands that add values to Windows Run registry keys, a common persistence technique.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium140Free2021-06-28