Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,301 rules
Windows: Alert on csc.exe Executing from User-Writable or Suspicious Paths
Alerts when csc.exe is launched from user/temp-like paths, indicating potential on-the-fly .NET compilation.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2019-08-24Windows PowerShell Base64 Command Line Executing IEX
Identifies Windows PowerShell processes with Base64-encoded command-line content that contains an IEX execution pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2310Free2019-08-23Windows: WmiPrvSE.exe Spawning a Child Process
Identifies child processes created by WmiPrvSE.exe on Windows, highlighting potential WMI-based execution attempts.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium92Free2019-08-15Windows Security: Non-System SeTakeOwnershipPrivilege granted on SCM database object
Flags non-system users requesting SeTakeOwnershipPrivilege on the SCM database object servicesactive in Windows Security 4674.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowssecurityMedium151Free2019-08-15Windows Security: SysKey-related LSA Registry Key Access (4656/4663)
Alerts on access to LSA registry keys used to compute SysKey based on Windows Security handle and registry object events.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh152Free2019-08-12Windows Security Event 4656: Non-system handle failure to SCM database object
Alerts on failed SCM database handle requests for ServicesActive from non-system logons using Windows Security Event ID 4656.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium253Free2019-08-12Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Flags Windows handle requests to registry keys ending with \SAM using Security EventID 4656.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh122Free2019-08-12Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowsps_moduleHigh103Free2019-08-10Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Flags Windows telemetry indicating a remote PowerShell session startup using wsmprovhost.exe with a specified host parameter.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsps_classic_startLow62Free2019-08-10Windows Security: Network Access to protected_storage (IPC)
Flags Windows network share access to protected_storage through IPC from Security event 5145.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh83Free2019-08-10Windows Security Event 4692 Detecting DPAPI Domain Master Key Backup Attempt
Flags Windows Event ID 4692 indicating an attempt to back up the DPAPI domain master key.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium234Free2019-08-10Windows: MMC spawning command-line executables
Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.
Karneades, Swisscom CSIRT, Huntrule TeamWindowsprocess_creationHigh101Free2019-08-05Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.
Nik Seetharaman, Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2019-07-31Windows Security: AD object replication attempted by non-machine account (Event ID 4662)
Alerts on AD replication-related object access events where the requester is not a machine account.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical103Free2019-07-26Windows regsvr32 Executes DLL with Uncommon Extension in Command Line
Alerts when regsvr32.exe is launched with a DLL extension pattern that is not in the common list.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium295Free2019-07-17