Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,301 rules
Windows Local User Creation (Security Event 4720)
Flags Windows Security Event ID 4720 indicating a local user account was created.
Patrick Bareiss, Huntrule TeamWindowssecurityLow3210Free2019-04-18Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowswmi_eventHigh113Free2019-04-15Windows: Suspicious Service Installation via Registry ImagePath Outside system32
Alerts on NalDrv/PROCEXP152 service ImagePath registry entries configured outside the expected system32 driver path.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsregistry_setMedium42Free2019-04-08Windows Suspicious PROCEXP152.sys Creation in Local Temp Folder
Flags creation of PROCEXP152.sys in AppData\Local\Temp, excluding events from common Sysinternals executables.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsfile_eventMedium209Free2019-04-08Windows Security Event 4673: SeLoadDriverPrivilege Use by Non-Whitelisted Processes
Flags Windows Event 4673 instances where SeLoadDriverPrivilege is exercised, suggesting attempts to load or unload kernel-mode drivers.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowssecurityMedium108Free2019-04-08WmiPrvSE.exe Spawned PowerShell Child Process on Windows
Alerts on PowerShell spawning from WmiPrvSE.exe, a possible indicator of WMI-based remote execution.
Markus Neis @Karneades, Huntrule TeamWindowsprocess_creationMedium73Free2019-04-03Windows Security 5145 Network Share Access to Sensitive File Extensions
Alerts when Windows users access network-shared files with extensions commonly targeted for credential or data collection.
Samir Bousseaden, Huntrule TeamWindowssecurityMedium362Free2019-04-03Windows GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Writes (Security 5136/5145)
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh156Free2019-04-03Windows Security 4661 Detects Privileged AD User/Group SID Enumeration via SAM
Identifies SAM_USER/SAM_GROUP access events (4661) aimed at privileged SIDs or names containing 'admin' while ignoring computer accounts.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh357Free2019-04-03Windows Security 5136: Modify AD ACL for DCSync Extended Right via ntSecurityDescriptor
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, Huntrule TeamWindowssecurityHigh284Free2019-04-03Windows Suspicious EXE in User Directory Launched by Microsoft Office Applications
Alert on Office spawning a .exe from C:\users\ (except when the child is Teams.exe).
Jason Lynch, Huntrule TeamWindowsprocess_creationHigh61Free2019-04-02Windows Security Logon Event ID 4800: Workstation Lock After Inactivity
Locked Workstation
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityInformational337Free2019-03-26Windows ADSI Schema Cache (.sch) File Creation by Uncommon Process
Alerts on .sch cache file creation in the Windows SchCache directory by uncommon executables.
xknow @xknow_infosec, Tim Shelton, Huntrule TeamWindowsfile_eventMedium199Free2019-03-24Windows Security Event 5136: Suspicious LDAP attribute display names used
Alerts on Event 5136 containing specific LDAP display names indicative of LDAP-based data exchange.
xknow @xknow_infosec, Huntrule TeamWindowssecurityHigh115Free2019-03-24Windows ETW Trace Evasion via Clearing/Disabling Logs or Providers
Identifies command-line attempts to clear/disable ETW traces or remove/modify ETW providers on Windows.
"@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule Team"Windowsprocess_creationHigh152Free2019-03-22