Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
Windows Process Creation: Detect reg.exe Add Control Panel CPL Items
Alerts on reg.exe adding Control Panel CPL items via CurrentVersion\Control Panel\CPLs, a common vector for stealthy execution/persistence.
Kyaw Min Thein, Furkan Caliskan (@caliskanfurkan_), Huntrule TeamWindowsprocess_creationHigh71Free2020-06-22Windows Process Creation: IE Security Registry Values Disabled via Command Line
Alerts on Windows command lines that set IE hardening-related registry values to disable security features.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3610Free2020-06-19Windows Process Creation: Possible Path Traversal in cmd.exe Command Line
Alerts on Windows cmd.exe executions with "../.." path traversal indicators in parent/child command lines.
xknow @xknow_infosec, Tim Shelton, Huntrule TeamWindowsprocess_creationHigh425Free2020-06-11Windows Pcap Driver Installation via EID 4697 ServiceFileName
Flags Windows driver install events (Security 4697) where the service file name matches known Pcap-related driver keywords.
Cian Heasley, Huntrule TeamWindowssecurityMedium131Free2020-06-10Windows file indicators for Octopus Scanner malware artifacts
Alerts on Windows file activity for Octopus Scanner-related filenames (Cache134.dat, ExplorerSync.db) in AppData.
NVISO, Huntrule TeamWindowsfile_eventHigh181Free2020-06-09Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Alerts on Windows consent-store registry entries showing webcam/microphone access tied to Temp or public user paths.
Den Iuzvyk, Huntrule TeamWindowsregistry_eventHigh112Free2020-06-07Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Identifies Windows processes interacting with non-packaged app consent entries for microphone and webcam access.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityMedium121Free2020-06-07Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags
Alerts on Sysmon registry sets that set .NET ETWEnabled/COMPlus ETW flags to 0, impairing ETW-based telemetry.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh213Free2020-06-05Windows Registry ETW Logging Disabled for .NET via Security Event 4657
Alerts when .NET ETW logging is disabled via registry changes (ETWEnabled or COMPlus ETW settings) using Event ID 4657.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh172Free2020-06-05Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Identifies Windows PowerShell command lines commonly used by Covenant launchers, including hidden/encoded execution patterns.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2020-06-04Windows: Renamed Sysinternals DebugView Process Execution
Flags Windows executions labeled as Sysinternals DebugView when the image is not the original Dbgview.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh124Free2020-05-28Windows: New Executables Named After System Processes in Non-System Paths
Alerts on creation of executables named like common system processes in unexpected Windows directories.
Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium91Free2020-05-26Windows netsh.exe Whitelists Allowed Program from Suspicious Path in Firewall
Flags netsh.exe firewall allow rules that whitelist a program located in suspicious Windows filesystem paths.
Sander Wiebing, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh435Free2020-05-25Windows RDP Port 3389 Allowed via netsh.exe Firewall Rule Creation
Flags netsh.exe commands that add firewall rules allowing TCP port 3389 (RDP).
Sander Wiebing, Huntrule TeamWindowsprocess_creationHigh364Free2020-05-23Windows Registry: Office VBAWarning Disabled (VBAWarnings set to 1)
Alerts on Security\VBAWarnings being set to DWORD 0x00000001, enabling all Office VBA macros.
Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh92Free2020-05-22