Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,289 rules
BITS Payload Downloaded via PowerShell (via powershell)
This rule detects downloads a payload by abusing BITS software. For more precise information, inspect "Bits-client" event log and search for ID 59 and 60.
HuntRule TeamWindowspowershellMedium10Premium2026-08-31Malicious WMI Spwaning PowerShell Process - WMImplant (via process_creation)
This rule detects wMIimplant.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Obfuscated Encoded PowerShell Payload Deployed - PowerShell (via powershell)
This rule detects deployed a service pointing to a hidden and encoded PowerShell payload.
HuntRule TeamWindowspowershellHigh50Premium2026-08-31Malicious Scheduled Task Created and Deleted Fastly - ATexec.py (via security)
This rule detects abuse task scheduler capacities to execute commands or elevate privileges.
HuntRule TeamWindowssecurityHigh30Premium2026-08-31SharpHound Host Enumeration Over Kerberos (via security)
This rule detects detect if a source host is requesting multiple Kerberos Service tickets (TGS) for different assets in a short period of time.
HuntRule TeamWindowssecurityMedium10Premium2026-08-31Malicious Event Log Cleared Using Diagnostics - Via PowerShell (via powershell)
This rule detects clear the event logs.
HuntRule TeamWindowspowershellHigh60Premium2026-08-31DoT (DNS Over TLS) Activation - Command (via process_creation)
This rule detects enable DNS over TLS in order to evade detection for command and control purposes.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-08-31Suspicious System Time Changed (via security)
This rule detects change the system time to evade defense. Check also if NewTime is different from PreviousTime to reduce false positives.
HuntRule TeamWindowssecurityMedium20Premium2026-08-31Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
This rule detects connect to a Windows host using the SSH protocol.
HuntRule TeamWindowssecurityMedium120Premium2026-08-31SPN Enumeration Previous to Kerberoasting Attack - Native Commands (via process_creation)
This rule detects retrieve SPN using commandline and native tools.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Suspicious Modification of a Sensitive Group Policy - GPO (via security)
This rule detects will attempt to take control over a group policy.
HuntRule TeamWindowssecurityMedium40Premium2026-08-31Malicious Edge Abuse for Payload Download via Console (via process_creation)
This rule detects attemptes to download a payload directly via console.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-31Obfuscated Certutil Payload Obfuscation - Command (via process_creation)
This rule detects abuse certutil command to download obfuscated malicious payload. Tools like Tchopper can trigger this rule.
HuntRule TeamWindowsprocess_creationHigh110Premium2026-08-31Malicious User Account Created by a Computer Account (via security)
This rule detects would abuse some privileges while realying host credentials to escalate privileges.
HuntRule TeamWindowssecurityHigh60Premium2026-08-31Malicious Netsh Helper DLL Abuse - Process (via process_creation)
This rule detects abuses the Netsh DLL feature to perform some code execution.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31