Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
Windows Registry Set AccessVBOM DWORD=1 Disables Access Security for Access VBA
Alerts on Windows registry changes setting Security\AccessVBOM to DWORD 1, disabling VBA trust access to bypass Office warnings.
Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh375Free2020-05-22Windows: CrackMapExec PowerShell obfuscation via join/split static patterns
Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.
Thomas Patzke, Huntrule TeamWindowsprocess_creationHigh81Free2020-05-22Windows NTLM Logon to TERMSRV on Non-Domain Hosts
Alerts on Windows NTLM events tied to TERMSRV targets that may be non-domain hosts, suggesting potential RDP access.
James Pemberton, Huntrule TeamWindowsntlmMedium115Free2020-05-22Windows Network Connections Initiated by Notepad.exe
Alerts when notepad.exe initiates an outbound network connection, excluding typical printing traffic on port 9100.
EagleEye Team, Huntrule TeamWindowsnetwork_connectionHigh196Free2020-05-14Windows: Detect rar.exe Archive Creation Using Password or Compression Options
Alerts on rar.exe command lines that include both password protection (-hp) and additional compression/archive flags.
"@ROxPinTeddy, Huntrule Team"Windowsprocess_creationHigh308Free2020-05-12Windows: Advanced IP Scanner (PUA) Execution via Process Creation
Identifies Windows processes running Advanced IP Scanner using filename/description and command-line arguments.
Nasreddine Bencherchali (Nextron Systems), @ROxPinTeddy, Huntrule TeamWindowsprocess_creationMedium366Free2020-05-12Advanced IP Scanner Execution from Temp Folder via Windows File Events
Flags file activity targeting Advanced IP Scanner 2 under a Windows user Temp directory.
"@ROxPinTeddy, Huntrule Team"Windowsfile_eventMedium193Free2020-05-12Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
NVISO, Huntrule TeamWindowsfile_eventHigh82Free2020-05-11Windows Security Log: Metasploit SMB NTLM Logon (4624/4625, 4776)
Detects Metasploit-linked NTLM SMB authentication activity using Windows 4624/4625 and 4776 with 16-char workstation names.
Chakib Gzenayi (@Chak092), Hosni Mribah, Huntrule TeamWindowssecurityHigh3910Free2020-05-06Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Alerts on Windows failed logons (4625) originating from IPs outside private/local ranges.
NVISO, Huntrule TeamWindowssecurityMedium356Free2020-05-06Windows Fax Service ualapi.dll Side-Loading via fxssvc.exe
Flags fxssvc.exe loading ualapi.dll from unexpected paths, indicating potential DLL side-loading for privilege escalation.
NVISO, Huntrule TeamWindowsimage_loadHigh72Free2020-05-04Windows AppCompatFlags Store New Application Registry Entries
Alerts on new writes to the AppCompat Compatibility Assistant store registry path, indicating first-time application behavior.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setInformational3410Free2020-05-02Windows Registry Deletion of Shell Open Command COM Hijacking Key Paths
Flags registry deletions of \shell\open\command paths that may indicate removal of COM hijacking execution entries.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_deleteMedium103Free2020-05-02Windows sdclt.exe Spawned with High Integrity (Possible UAC Bypass)
Alerts on sdclt.exe launching as High integrity, indicating possible elevated execution consistent with UAC bypass attempts.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium92Free2020-05-02Windows Process Creation: .NET ETW Logging Environment Variables Set via Command Line
Flags process command lines setting COMPlus_ETWEnabled/COMPlus_ETWFlags, potentially impairing ETW logging for .NET.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationHigh346Free2020-05-02