Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
Windows CreateMiniDump.exe HackTool Execution via Process Creation
Detects the execution of CreateMiniDump.exe using image name and a specific IMPHASH.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2019-12-22Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Alerts on SharpHound/Bloodhound-like processes launching with discovery-focused command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh174Free2019-12-20Windows Process Creation: IIS appcmd Native Module Installation via Command Line
Alerts on appcmd.exe commands installing IIS native-code modules using a -name: parameter, excluding iissetup-launched setups.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium92Free2019-12-11Successful Windows Account Logon via WMI (4624 with WmiPrvSE.exe)
Flags successful 4624 logons tied to WmiPrvSE.exe, indicating WMI-driven authentication on Windows.
Thomas Patzke, Huntrule TeamWindowssecurityLow83Free2019-12-04Windows Security: Detect Domain Trust Creation (Event ID 4706)
Alerts on Windows Event ID 4706 indicating a new trust was created to a domain.
Thomas Patzke, Huntrule TeamWindowssecurityMedium359Free2019-12-03Windows Security: Failed Code Integrity Checks (Event 5038/6281)
Alerts on Windows Security code integrity failures (Event 5038/6281) that may indicate modified or corrupted binaries.
Thomas Patzke, Huntrule TeamWindowssecurityInformational282Free2019-12-03Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Flags Windows Event ID 6416 entries where a DiskDrive/USB Mass Storage Device is detected as connected.
Keith Wright, Huntrule TeamWindowssecurityLow96Free2019-11-20Windows ProcDump Execution via Renamed Binary
Flags renamed ProcDump usage on Windows by matching procdump indicators and dump flags while excluding known executable names.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2019-11-18Windows Security: Anonymous Logon (4624 LogonType 3) with Loopback IPs
Alerts on Windows 4624 LogonType 3 with ANONYMOUS LOGON and loopback IPs, matching RottenPotato-like patterns.
"@SBousseaden, Florian Roth, Huntrule Team"WindowssecurityHigh111Free2019-11-15Windows msiexec.exe Execution from Uncommon Directory
Alerts when msiexec.exe starts from a non-standard path, which may indicate masquerading.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3410Free2019-11-14Windows Image Load: System.Management.Automation DLL Loaded by Non-PowerShell Process
Alerts when a non-PowerShell executable loads System.Management.Automation.dll on Windows, indicating possible PowerShell execution in another process.
Tom Kern, oscd.community, Natalia Shornikova, Tim Shelton, Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium71Free2019-11-14Windows Process Creation: Detect Obfuscated PowerShell IEX Invocation from Invoke-Obfuscation
Detects PowerShell commands showing obfuscation markers consistent with Invoke-Obfuscation-powered IEX invocation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsprocess_creationHigh143Free2019-11-08PowerShell: Obfuscated IEX Invocation via Invoke-Obfuscation String/Variable Patterns
Alerts on obfuscated PowerShell IEX invocation strings built from Invoke-Obfuscation style concatenation patterns in ScriptBlockText.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsps_scriptHigh124Free2019-11-08PowerShell Module Obfuscated IEX Invocation via Invoke-Obfuscation Payload Patterns
Alerts when PowerShell module payloads contain patterns consistent with obfuscated IEX generation via Invoke-Obfuscation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsps_moduleHigh71Free2019-11-08Windows System Service Creation of Obfuscated PowerShell IEX (Invoke-Obfuscation)
Flags Windows service creations whose ImagePath contains obfuscated PowerShell IEX invocation strings.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowssystemHigh3010Free2019-11-08