Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,304 rules
Windows Network Share File Transfers Targeting Credential and Memory Dump Paths
Alerts on network share access to credential-related files using Windows Security Event 5145.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowssecurityMedium154Free2019-10-22Windows Network Tool Use for Possible Packet Sniffing (tshark/windump)
Alerts on Windows executions of tshark or windump that indicate potential passive network traffic capture.
Timur Zinniatullin, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium83Free2019-10-21Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow335Free2019-10-21Windows: Detect sc.exe Service Config binPath Changes to Suspicious Commands/Paths
Alerts when sc.exe updates a service binPath to point at suspicious commands or commonly abused directories.
Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2019-10-21Windows reg.exe Registry Query Reconnaissance (Process Creation)
Alerts on reg.exe process executions performing registry queries against high-value configuration and service keys.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium4310Free2019-10-21Windows Rar.exe Files Added to Archive Activity
Alerts when Windows rar.exe is used to add files to an archive using the " a " command-line pattern.
Timur Zinniatullin, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationLow169Free2019-10-21Windows: net.exe used to start a service with the start flag
Identifies Windows processes using net.exe/net1.exe with ' start ' to start services.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21Windows Msxsl.exe Execution
Flags execution of the Windows MSXSL utility (msxsl.exe), which can be abused to process attacker-controlled XSL inputs.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium70Free2019-10-21Windows Process: File Association Changes via assoc Command
Alerts on cmd.exe launches running the assoc command to modify Windows default file associations.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21PowerShell ScriptBlock Winlogon Registry Modification via CurrentVersion\Winlogon
Detects PowerShell script blocks that modify Winlogon helper registry keys via Set-ItemProperty or New-Item on Windows.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium102Free2019-10-21Windows Process Creation: Suspicious CHCP Code Page Switch to Rare Locale
Alerts on suspicious chcp.com usage that switches Windows code pages to specific rare identifiers in process creation logs.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium444Free2019-10-14Windows Registry: Suspicious Keyboard Layout Preload in User Session
Detects user-hive registry changes that preload Persian (Iranian) or Vietnamese keyboard layouts under Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setMedium322Free2019-10-12Windows Screen Capture via psr.exe (Problem Steps Recorder) Execution
Flags psr.exe launched with /start or -start, indicating potential user screen and click recording.
Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationMedium73Free2019-10-12Windows OpenWith.exe Launches Another Binary via /c
Flags Windows OpenWith.exe executions that include '/c', indicating it launched another binary.
Beyu Denis, oscd.community (rule), @harr0ey (idea), Huntrule TeamWindowsprocess_creationHigh42Free2019-10-12Windows Devtoolslauncher.exe LaunchForDeploy Executes a Specified Binary
Alerts when devtoolslauncher.exe runs with LaunchForDeploy, indicating it may launch another binary on Windows.
Beyu Denis, oscd.community (rule), @_felamos (idea), Huntrule TeamWindowsprocess_creationHigh337Free2019-10-12