Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,296 rules
Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2018-10-30Windows: Local user account creation via net.exe or net1.exe
Alerts on net.exe/net1.exe launching with "user" and "add" to create local accounts on Windows.
Endgame, JHasenbusch (adapted to Sigma for oscd.community), Huntrule TeamWindowsprocess_creationMedium40Free2018-10-30Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Flags PowerShell (powershell.exe/pwsh) process executions with command-line indicators consistent with XOR/obfuscated scripting.
Sami Ruohonen, Harish Segar, Tim Shelton, Teymur Kheirkhabarov, Vasiliy Burov, oscd.community, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium247Free2018-09-05Windows PowerShell Suspicious Encoded Command-Line Execution
Alerts on PowerShell launched with encoded-command switches and embedded encoded content patterns in the command line.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, Anton Kutepov, oscd.community, Huntrule TeamWindowsprocess_creationHigh238Free2018-09-03Windows Process in Suspicious Folder Initiating Network Connections to File Sharing Domains
Alerts on outbound connections to file sharing domains from Windows executables running out of suspicious temp/recycle/task paths.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh423Free2018-08-30Windows LSASS process access blocked by Attack Surface Reduction (Windows Defender event 1121)
Alerts on windefend EventID 1121 for blocked access to lsass.exe, excluding common benign process callers.
Markus Neis, Huntrule TeamWindowswindefendHigh171Free2018-08-26Windows Registry Run Key Set to Executable in Suspicious Folder
Flags new Windows Run key values pointing to executables in suspicious folders, excluding known update/Spotify patterns.
Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh135Free2018-08-25Windows Process Creation: PowerShell Command Execution Hidden in DLL Invocation
Flags DLL-invoking Windows binaries whose command lines include PowerShell execution strings.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2018-08-25Windows: .NET Reflection Attempt to Disable AMSI via amsiInitFailed
Alerts on Windows command lines referencing amsiInitFailed and .NET reflection patterns to disable AMSI scanning.
Markus Neis, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh442Free2018-08-17PowerShell NTFS Alternate Data Stream Writes via set-content/add-content
Alerts on PowerShell Set/Add-Content operations that specify -Stream, indicating potential NTFS Alternate Data Stream writes.
Sami Ruohonen, Huntrule TeamWindowsps_scriptHigh262Free2018-07-24Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
Markus Neis, Huntrule TeamWindowsfile_eventHigh203Free2018-07-24Windows Registry Explorer Run Key Persistence Pointing to Suspicious Paths
Alerts on writes to the Explorer Run policy registry key with details pointing to suspicious filesystem paths.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsregistry_setHigh122Free2018-07-18Windows Registry Events: CMSTP Execution via cmmgr32.exe TargetObject
Flags registry events referencing \cmmgr32.exe, consistent with CMSTP-related execution behavior on Windows.
Nik Seetharaman, Huntrule TeamWindowsregistry_eventHigh91Free2018-07-16Windows CMSTP Process Spawning Child Process
Alerts on child processes spawned by Windows cmstp.exe, a common signal for CMSTP abuse.
Nik Seetharaman, Huntrule TeamWindowsprocess_creationHigh236Free2018-07-16Windows Process Access to cmlua.dll by CMSTP Connection Manager Profile Installer
Alerts on Windows process access events whose call trace includes cmlua.dll, indicating potential CMSTP-related execution.
Nik Seetharaman, Huntrule TeamWindowsprocess_accessHigh438Free2018-07-16