Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
Windows rundll32 WebDAV Client Execution (davclnt.dll DavSetCookie)
Flags svchost.exe spawning rundll32.exe to run davclnt.dll,DavSetCookie, consistent with WebDAV client execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium60Free2020-05-02PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Flags Windows command lines containing Get-Clipboard, indicating potential clipboard data collection via PowerShell.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2020-05-02Windows PowerShell Get-Clipboard Command Execution
Flags PowerShell activity that includes the Get-Clipboard command, which may be used to collect clipboard contents.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleMedium289Free2020-05-02PowerShell Decompress via Expand-Archive
Alerts on PowerShell usage of Expand-Archive, a common decompression step attackers may use to unpack files.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleInformational93Free2020-05-02Windows Startup Directory File Writes for Persistence
Alerts on file writes into the Windows Startup folder that may indicate user-level persistence.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventMedium2410Free2020-05-02Windows File Deletion Using Sysinternals SDelete (SDelete rename suffixes)
Flags Windows file deletions targeting filenames ending in .AAA or .ZZZ consistent with SDelete-style artifact removal.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_deleteMedium94Free2020-05-02Windows findstr Launches .lnk via Command Line
Flags find.exe or findstr.exe processes whose command lines end with a .lnk file.
Trent Liffick, Huntrule TeamWindowsprocess_creationMedium71Free2020-05-01Windows winget Installs Applications Using Local Manifest File
Flags winget.exe install commands that specify a local manifest file via -m/--manifest.
Sreeman, Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium101Free2020-04-21Windows Process Command Lines Writing Malicious Files to C:\Windows\Fonts
Flags Windows command lines that create or copy files into C:\Windows\Fonts\ using suspicious file extensions.
Sreeman, Huntrule TeamWindowsprocess_creationMedium356Free2020-04-21Windows Netsh.exe WLAN profile key clearing used for WiFi credential harvesting
Detects netsh.exe command-line activity targeting WLAN and clearing keys, indicative of potential WiFi credential harvesting on Windows.
Andreas Hunkeler (@Karneades), oscd.community, Huntrule TeamWindowsprocess_creationMedium92Free2020-04-20Windows: Process Execution of Suspicious hxtsr.exe (Outside WindowsApps)
Alerts when hxtsr.exe runs from a non-expected WindowsApps Microsoft.WindowsCommunicationsApps location.
Sreeman, Huntrule TeamWindowsprocess_creationMedium246Free2020-04-17PowerShell Local User Creation via New-LocalUser
Flags PowerShell usage of New-LocalUser, indicating creation of a Windows local user.
"@ROxPinTeddy, Huntrule Team"Windowsps_scriptMedium40Free2020-04-11Windows: Alert on Suspicious HH.EXE Process Execution
Alerts on HH.exe execution where the command line references temp, downloads, Outlook, or other writable directories.
Maxim Pavlunin, Huntrule TeamWindowsprocess_creationHigh71Free2020-04-01Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2020-04-01Windows Security Event 4662: Non-Machine Account Reads Domain User Object Properties
Alert on AD user property read attempts in Windows Event 4662 from non-machine accounts.
Maxime Thiebaut (@0xThiebaut), Huntrule TeamWindowssecurityMedium93Free2020-03-30