Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,359 rules
Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssecurityHigh133Free2021-05-26Windows Named Pipe Creation Matching Cobalt Strike Default Pipe Prefixes
Flags Windows named pipe creation where PipeName matches known Cobalt Strike default pipe prefixes.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowspipe_createdCritical131Free2021-05-25Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Flags indicating PsExec/PAExec-style execution as LOCAL SYSTEM using cmd/powershell/pwsh in process command lines.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4110Free2021-05-22Windows Process Creation: Renamed PAExec Application Execution
Flags Windows executions of a renamed PAExec binary using process metadata and known IMPHASH values.
Florian Roth (Nextron Systems), Jason Lynch, Huntrule TeamWindowsprocess_creationHigh162Free2021-05-22Windows: WinRM Service Process Spawning Command-Line and Scripting Utilities
Flags suspicious child shells and admin utilities spawned by the WinRM host process (wsmprovhost.exe) on Windows.
Andreas Hunkeler (@Karneades), Markus Neis, Huntrule TeamWindowsprocess_creationHigh293Free2021-05-20PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh2310Free2021-05-18Windows Process Command Lines Indicating ngrok.exe Tunnel Setup
Detects Windows executions of ngrok.exe with TCP/HTTP tunneling and authtoken/start-all YAML configuration patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh221Free2021-05-14Windows: Detect Rclone command execution with exfiltration-oriented flags
Identifies likely rclone.exe exfiltration activity on Windows by matching command-line flags and rclone executable characteristics.
Bhabesh Raj, Sittikorn S, Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsprocess_creationHigh173Free2021-05-10Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.
Bhabesh Raj, Huntrule TeamWindowssystemCritical3010Free2021-05-06Windows whoami.exe Privilege Enumeration Using /priv Flag
Alerts on whoami.exe runs with /priv or -priv to enumerate current user privileges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2021-05-05Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh426Free2021-05-03Windows Security: Hidden Local User Account Creation (Event ID 4720)
Alerts on Windows 4720 local user creation for hidden accounts (username ending with '$'), excluding 'HomeGroupUser$'.
Christian Burkard (Nextron Systems), Huntrule TeamWindowssecurityHigh90Free2021-05-03Windows Process Access to svchost.exe with Credential Dumping Access Rights
Alerts on attempts to read svchost.exe memory consistent with credential dumping, excluding known benign callers.
Florent Labouyrie, Huntrule TeamWindowsprocess_accessHigh343Free2021-04-30PowerShell Defender Exclusion via Set/Add-MpPreference Command-Line Flags (Windows)
Detects PowerShell commands that add or set Microsoft Defender exclusions using Add/Set-MpPreference parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium316Free2021-04-29Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh447Free2021-04-23