Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,359 rules
Windows AMSI Provider Registry Key Deletion (HKLM\Software\Microsoft\AMSI)
Alerts on deletion of AMSI provider registry key entries under HKLM\Software\Microsoft\AMSI, potentially indicating AMSI inspection impairment.
frack113, Huntrule TeamWindowsregistry_deleteHigh172Free2021-06-07PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_classic_provider_startHigh403Free2021-06-07Windows Sysmon Configuration Event Where Sysmon Stops
Alert on Sysmon status showing a stop event concurrent with a Sysmon configuration state change.
frack113, Huntrule TeamWindowssysmon_statusHigh437Free2021-06-04Windows Sysmon error events indicating service configuration update failures
Flags Windows Sysmon errors for failed service configuration/driver update attempts that may indicate tampering.
frack113, Huntrule TeamWindowssysmon_errorHigh172Free2021-06-04Windows Process Creation: SDelete Used for File Overwrite
Alerts when sdelete.exe runs in a way consistent with file overwrite to impede forensic recovery.
frack113, Huntrule TeamWindowsprocess_creationHigh296Free2021-06-03Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
frack113, Huntrule TeamWindowsps_classic_startHigh369Free2021-06-03Windows Rundll32 Loads DLL Export StartNodeRelay (F-Secure C3)
Flags rundll32.exe launching a DLL that references the StartNodeRelay export in its command line.
Alfie Champion (ajpc500), Huntrule TeamWindowsprocess_creationCritical435Free2021-06-02Windows Rundll32 Used to Start Cobalt Strike DLL Load via StartW
Alerts on rundll32.exe command lines that include a .dll and StartW function, consistent with Cobalt Strike DLL loading.
Wojciech Lesicki, Huntrule TeamWindowsprocess_creationHigh163Free2021-06-01Windows Security Event 4663: ISO CD-ROM device mount activity
Alerts on Windows file-access events consistent with ISO mounting by activity under \\Device\\CdRom.
Syed Hasan (@syedhasan009), Huntrule TeamWindowssecurityMedium131Free2021-05-29Windows rundll32.exe Started Without Command-Line Parameters
Alerts on Windows process launches of rundll32.exe with no parameters, excluding likely benign parent paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-05-27Windows: regedit.exe launched with TrustedInstaller or Process Hacker parent
Alerts when regedit.exe is launched by TrustedInstaller.exe or ProcessHacker.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh394Free2021-05-27Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Flags Windows service installs for ProcessHacker-prefixed services running as LocalSystem.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh231Free2021-05-27Windows: Rclone Configuration File Creation via rclone config path
Alerts on creation of rclone config files under a Windows user profile path.
Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsfile_eventMedium183Free2021-05-26Windows DNS Queries for userstorage.mega.co.nz Subdomain
Alerts on DNS queries referencing MEGA userstorage subdomains from Windows hosts.
Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsdns_queryMedium122Free2021-05-26Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssystemCritical245Free2021-05-26