Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
Windows Defender Windefend AMSI Detection (Event ID 1116)
Flags Windows Defender AMSI detections via windefend Event ID 1116 with SourceName set to AMSI.
Bhabesh Raj, Huntrule TeamWindowswindefendHigh70Free2020-09-14Windows Registry Set: .NET COR/CORECLR Profiling Environment Variables Enabled
Alerts on registry writes enabling .NET CLR/CORECLR profiling variables like COR_ENABLE_PROFILING and COR_PROFILER.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Jimmy Bayne (@bohops), Huntrule TeamWindowsregistry_setMedium447Free2020-09-10Windows Process Creation: MpCmdRun.EXE Used to Download Files via DownloadFile url
Alerts when MpCmdRun.exe is executed with DownloadFile and url, indicating Defender utility file download behavior.
Matthew Matchen, Huntrule TeamWindowsprocess_creationHigh191Free2020-09-04WMI scrcons.exe Loading Script and WMI DLLs via Image Load (Windows)
Alerts when scrcons.exe loads vbscript/wbem/WMI script DLLs, suggesting WMI ActiveScriptEventConsumer activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium113Free2020-09-02Windows Process Creation: Mouse Lock Execution with “Misc314” Indicator
Alerts on Windows executions of Mouse Lock where Company includes “Misc314” and CommandLine contains “Mouse Lock_”.
Cian Heasley, Huntrule TeamWindowsprocess_creationMedium111Free2020-08-13Windows Defender windefend Event 1013: Malware detection history deletion
Alerts when Windows Defender deletes its malware/PUA detection history via windefend Event ID 1013.
Cian Heasley, Huntrule TeamWindowswindefendInformational318Free2020-08-13Windows Security Event 5145: SMB Write Access to Admin Share (C$)
Flags non-machine accounts writing via SMB to the C$ administrative share using Security EventID 5145.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh152Free2020-08-06Windows windefend Event ID 5012: Windows Defender virus scanning disabled
Flags when Windows Defender disables virus scanning via windefend Event ID 5012.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh132Free2020-07-28Windows windefend: Windows Defender threat detection and mitigation events
Alerts on windefend events indicating Windows Defender malware detection and potential remediation activity.
Ján Trenčanský, Huntrule TeamWindowswindefendHigh183Free2020-07-28Windows windefend EventID 5001: Windows Defender real-time protection disabled
Flags windefend Event ID 5001 indicating Windows Defender real-time protection was disabled.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh172Free2020-07-28Windows windefend: Microsoft Defender malware and PUA scanning disabled (Event ID 5010)
Flags Windows Defender disabling malware and PUA scanning using Windefend Event ID 5010.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh163Free2020-07-28Windows Defender antimalware grace period expired (Event ID 5101)
Alerts when Windows Defender signals its antimalware grace period expired via windefend Event ID 5101.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh101Free2020-07-28Windows Service Control Manager: Windows Defender Threat Protection Disabled
Flags Service Control Manager events where the Windows Defender Threat Protection (Defender Antivirus) service is stopped.
Ján Trenčanský, frack113, Huntrule TeamWindowssystemMedium468Free2020-07-28Windows webserver-spawned recon commands probing scripting tool help (perl/python/wget)
Flags webserver child processes running perl/python/python3/wget help commands to probe available tooling on the host.
Cian Heasley, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2020-07-22Windows DLL Load Indicates Potential Azure Browser SSO OAuth Token Request Abuse
Alerts on MicrosoftAccountTokenProvider.dll loads on Windows, with process-based exclusions, as a signal for potential Azure Browser SSO token activity.
Den Iuzvyk, Huntrule TeamWindowsimage_loadLow171Free2020-07-15