Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,304 rules
Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical111Free2019-10-11PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh60Free2019-10-08PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh297Free2019-10-08Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders
Alerts on registry Run key writes originating from Downloads or temporary Outlook/IE directories on Windows.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poude (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh113Free2019-10-01Suspicious Windows Program Execution from Outlook Temporary Internet Files Folder
Alerts on process executions whose image path points to Outlook temporary files (Content.Outlook).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2019-10-01Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2019-09-26Windows fsutil.exe Suspicious USN Journal and File Zeroing Parameters
Alerts when fsutil.exe is run with USN journal deletion/creation or setZeroData-style file zeroing commands.
Ecco, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationHigh117Free2019-09-26Windows Registry: Enable WDigest UseLogonCredential (Use clear-text logon credential setting)
Flags registry writes that enable WDigest UseLogonCredential, turning on potential clear-text credential storage.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh203Free2019-09-12Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Alerts when wsmprovhost.exe is seen as a process or parent process, indicating remote PowerShell via WinRM.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium50Free2019-09-12Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents
Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.
Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements), Huntrule TeamWindowsprocess_creationLow91Free2019-09-12Windows Named Pipe Created for PowerShell PSHost Instance
Alerts on named pipe creation with a \PSHost prefix, indicating PowerShell host-related activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspipe_createdInformational30Free2019-09-12Windows Named Pipe Creation: Alternate PowerShell Host via \PSHost
Alerts on creation of \PSHost named pipes to identify alternate PowerShell host usage via Windows pipe events.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowspipe_createdMedium52Free2019-09-12Windows: WinRM inbound network connections to ports 5985/5986 for PowerShell remoting
Alerts on WinRM inbound connections (ports 5985/5986) consistent with remote PowerShell remoting activity.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh383Free2019-09-12Windows Security: Detect WRITE_DAC on AD DS objects (Event ID 4662)
Flags AD DS Security Event 4662 activity indicating WRITE_DAC permission changes on domain objects.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical101Free2019-09-12Windows Suspicious Debugger Registration via Image File Execution Options
Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh92Free2019-09-06