Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
Bhabesh Raj, Huntrule TeamWindowswindefendHigh133Free2020-07-14Windows Sysmon Operational Channel Reference Deleted via Security Event
Detects Security log events showing Sysmon Operational channel being disabled via channel reference deletion-like changes.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh121Free2020-07-14Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2020-07-09Windows Process Execution of DIT Snapshot Viewer (ditsnap.exe)
Alerts on execution of the DIT snapshot viewer tool ditsnap.exe on Windows.
Furkan Caliskan (@caliskanfurkan_), Huntrule TeamWindowsprocess_creationHigh297Free2020-07-04Windows Process Execution: Copy From System Directories to Other Locations
Detects cmd.exe, PowerShell, and copy utilities copying files from System32/SysWOW64/WinSxS to other locations on disk.
Florian Roth (Nextron Systems), Markus Neis, Tim Shelton (HAWK.IO), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2020-07-03Windows desktopimgdownldr Suspicious URL and Registry Modification via Command Line
Flags desktopimgdownldr command lines indicating potential external file download or personalization registry deletion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh468Free2020-07-03Windows curl.exe Suspicious Download to Local File Paths
Flags curl.exe executions on Windows that appear to download to local files in suspicious directories with risky file extensions.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2020-07-03Windows Desktop Image Downloader Targeting Lock Screen Images with Suspicious File Types
Alerts on desktopimgdownldr-style lock screen image target writes to non-system paths with suspicious filename characteristics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh273Free2020-07-03Windows Registry Printer Driver Installations with Empty Manufacturer Field
Alerts on Windows registry printer driver environment updates where Manufacturer is set to empty.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh309Free2020-07-01Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Alerts on AppLocker event IDs showing blocked execution of apps, scripts, DLLs, MSI, or packaged apps.
Pushkarev Dmitry, Huntrule TeamWindowsapplockerMedium371Free2020-06-28Windows Security Log: Denied Remote Desktop Logon (Event ID 4825)
Flags Windows denied RDP connection attempts from users lacking permission to log on remotely (Event ID 4825).
Pushkarev Dmitry, Huntrule TeamWindowssecurityMedium433Free2020-06-27Windows Registry Event Triggered by RedMimicry Winnti Playbook (HTMLHelp\data)
Alerts on Windows registry events targeting HKLM\SOFTWARE\Microsoft\HTMLHelp\data associated with the RedMimicry Winnti playbook.
Alexander Rausch, Huntrule TeamWindowsregistry_eventHigh122Free2020-06-24Windows process execution matching Winnti RedMimicry playbook (rundll32/cmd with temp batch and gthread/sigcmm DLLs)
Flags rundll32.exe/cmd.exe launches with Winnti-specific DLL and temp batch indicators.
Alexander Rausch, Huntrule TeamWindowsprocess_creationHigh40Free2020-06-24Suspicious WSMAN COM Provider Usage Without PowerShell Host (Windows)
Alerts on WSMAN COM provider activity where the host application is not PowerShell.exe in PowerShell Classic logs.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspowershell-classicMedium143Free2020-06-24Windows File Drops Matching Winnti Dropper Artifacts (gthread/sigcmm DLLs, tmp.bat)
Detects Windows file drops of specific DLLs and a Windows Temp batch filename pattern associated with a Winnti dropper scenario.
Alexander Rausch, Huntrule TeamWindowsfile_eventHigh139Free2020-06-24