Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,293 rules
Windows: Command-line execution using Sysinternals -accepteula flag
Alerts on Windows processes launched with the -accepteula flag, often associated with Sysinternals tool execution.
Markus Neis, Huntrule TeamWindowsprocess_creationLow92Free2017-08-28Windows WMI Persistence via Event Filter/Consumer Bindings and Filter Registration
Flags likely WMI-based persistence by spotting event filter/consumer bindings and WMI filter registrations tied to script/command-line consumers.
Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule TeamWindowswmiMedium234Free2017-08-22Windows WMI Persistence via Security Event 4662 on WMI subscription namespace
Alerts on Security Event 4662 indicating access to WMI Namespace objects with "subscription" in the name.
Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule TeamWindowssecurityMedium81Free2017-08-22Windows svchost.exe Spawned by Uncommon Parent Process
Alerts when svchost.exe starts with an unusual parent process name on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium83Free2017-08-15Windows Security: Account Encryption/Preauth/Delegation Flags Weakened in User Account Changes
Flags Windows Event ID 4738 user account changes that enable weaker encryption or related pre-auth behavior.
"@neu5ron, Huntrule Team"WindowssecurityHigh445Free2017-07-30Windows Security: SeEnableDelegationPrivilege Enabled via AD User Right (Event 4704)
Alerts when Event ID 4704 assigns SeEnableDelegationPrivilege, enabling control over other AD user objects.
"@neu5ron, Huntrule Team"WindowssecurityHigh401Free2017-07-30Windows Security Events Indicating File Deletion Attempts Using SDelete Extensions
Alerts on Windows security file access events for object names ending in .AAA or .ZZZ, consistent with secure deletion behavior.
Thomas Patzke, Huntrule TeamWindowssecurityMedium101Free2017-06-14Windows WCE wceaux.dll File Access via Security Event 4656/4663
Identifies Windows Security event activity involving access to the wceaux.dll library file.
Thomas Patzke, Huntrule TeamWindowssecurityCritical92Free2017-06-14Windows PsExec Service Execution via PSEXESVC.exe
Detects PsExec service execution by matching the PSEXESVC.exe process on Windows.
Thomas Patzke, Romaissa Adjailia, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2017-06-12Windows: PsExec Service File Creation via PSEXESVC.exe Written to Disk
Flags Windows file creation of \PSEXESVC.exe, indicating potential PsExec service deployment for remote execution.
Thomas Patzke, Huntrule TeamWindowsfile_eventLow152Free2017-06-12Windows PsExec Service Installation via Service Control Manager (Event ID 7045)
Flags Service Control Manager Event ID 7045 when a PSEXESVC service is installed with ImagePath ending in \PSEXESVC.exe.
Thomas Patzke, Huntrule TeamWindowssystemMedium141Free2017-06-12Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Alerts when RULER-labeled Windows Security events show NTLM auth (4776) plus 4624/4625 logons.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh297Free2017-05-31Windows Registry: DHCP Server Callout DLL and Enable Parameters Installation
Alerts on registry changes enabling and configuring DHCP Server callout DLLs via CalloutDlls and CalloutEnabled.
Dimitrios Slamaris, Huntrule TeamWindowsregistry_setHigh63Free2017-05-15Windows ETW: Kernel-General resets registry hive access bits in temp hive paths
Detects ETW EventID 16 when access bits are reset for Temp \SAM or \SECURITY hives.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh322Free2017-05-15Windows DHCP Server Error: Callout DLL Failed to Load
Flags DHCP Server events showing failure to load a configured Callout DLL (Event IDs 1031/1032/1034).
Dimitrios Slamaris, @atc_project (fix), Huntrule TeamWindowssystemHigh404Free2017-05-15