Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,357 rules
Windows Registry Run Key Modification via winekey or team9 backdoor
Detects registry Run key changes to "Backup Mgr" that may indicate persistence via winekey/team9.
omkar72, Huntrule TeamWindowsregistry_eventHigh191Free2020-10-30Windows PsExec Execution Triggered by psexec.exe Process Creation
Flags process creation of PsExec (psexec.exe / psexec.c), a tool often used for remote execution and potential lateral movement.
omkar72, Huntrule TeamWindowsprocess_creationMedium205Free2020-10-30Windows Credential Access via Reg Add in LSA Registry Paths
Alerts when reg add commands target LSA registry settings and scecli entries commonly abused for credential access.
Sreeman, Huntrule TeamWindowsprocess_creationMedium93Free2020-10-29Windows Process Creation: bitsadmin.exe BITS jobs with SetNotifyCmdLine or remote file additions
Alerts on bitsadmin.exe command lines using /SetNotifyCmdLine or /Addfile to execute after download or stage remote files.
Sreeman, Huntrule TeamWindowsprocess_creationMedium162Free2020-10-29Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh363Free2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventHigh162Free2020-10-29Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
Semanur Guneysu @semanurtg, oscd.community, Huntrule TeamWindowsprocess_creationHigh131Free2020-10-28Windows Registry Persistence via Office Test Startup Key
Flags registry changes to a Windows Office test startup key that may enable auto-execution of an arbitrary DLL.
omkar72, Huntrule TeamWindowsregistry_eventMedium456Free2020-10-25Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.
Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh272Free2020-10-23Windows Registry: Detect esentutl.exe activity under VSS service keys
Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh192Free2020-10-20Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_accessHigh171Free2020-10-20Windows DLL image load: credui.dll loaded by an uncommon process
Detects credui.dll or wincredui.dll being loaded by a process other than common system binaries.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium274Free2020-10-20Windows Event Log Detects Volume Shadow Copy Mounts (HarddiskVolumeShadowCopy, EventID 98)
Alerts when NTFS logs indicate a VSS (HarddiskVolumeShadowCopy) mount using EventID 98.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssystemLow468Free2020-10-20Windows Security: VSSAudit Event Source Registration (Event ID 4904/4905)
Alerts on VSSAudit security event source registration in Windows Security logs using Event IDs 4904/4905.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityInformational3610Free2020-10-20Windows RunOnce Execution via runonce.exe With AlternateShellStartup and /r
Alerts on runonce.exe executing with /AlternateShellStartup and /r, consistent with configured RunOnce persistence behavior.
Avneet Singh @v3t0_, oscd.community, Christopher Peacock @SecurePeacock (updated), Huntrule TeamWindowsprocess_creationLow163Free2020-10-18