Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,289 rules
Malicious WMI Registration - PowerShell (via powershell)
This rule detects createsan instance of a WMI class using tools like WMImplant or PowerLurk.
HuntRule TeamWindowspowershellHigh50Premium2026-08-31Malicious SQL Server Sqlcmd Utility Abuse for Privilege Escalation (via process_creation)
This rule detects uses sqlcmd utility to escalate privileges or introduce weaknesses.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Malicious User Application Credentials Dump via Network Share - DonPapi, Lazagne (via security)
This rule detects attempt to dump application credentials (Firefox, VNC, Google Chrome, ...) via network share.
HuntRule TeamWindowssecurityHigh40Premium2026-08-31NTFS Hard Link Creation (via process_creation)
This rule detects create a hard link.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-08-31In-Memory Security Package (SSP) Added - Reg via Command (via process_creation)
This rule detects adds a reference in the registry to a malicious SSP (Security Support Provider). Note that this rule will not work with "in memory" SSP injection (Mimikatz).
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Malicious Microsoft Defender Critical Security Components Disabled - PowerShell (via powershell)
This rule detects disable Defender security features in PowerShell.
HuntRule TeamWindowspowershellHigh80Premium2026-08-31Malicious Rubeus Kerberos Constrained Delegation Abuse - S4U2Proxy (via security)
This rule detects abuse Kerberos constrained delegation in order to escalate privileges.
HuntRule TeamWindowssecurityHigh50Premium2026-08-31Renamed Procdump Tool Used for Dumping LSASS Process (via process_creation)
This rule detects dump the LSASS process content using a renamed version of the Procdump tool.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
This rule detects register the SMBexec service to estasblish persistence.
HuntRule TeamWindowsregistry_eventHigh00Premium2026-08-31Malicious User Creation via Commandline (via process_creation)
This rule detects create a user via commandline.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-08-31Malicious Network Share Discovery And/or Connection via Commandline (via process_creation)
This rule detects enumerate or to establish a connection to a network share.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-08-31Malicious RDP Tunneling (via rdp)
This rule detects uses RDP tunneling to redirect traffic to a C&C target.
HuntRule TeamWindowsrdpHigh40Premium2026-08-31Malicious Service Permissions Hijacked for Privileges Abuse - Reg via PowerShell (via powershell)
This rule detects modify the permissions of a service using native PowerShell commands in order to abuse its privileges. Note that it requires PowerShell 7 or higher.
HuntRule TeamWindowspowershellHigh30Premium2026-08-31Malicious Windows Native Backup Deletion (via process_creation)
This rule detects delete existing Windows native backup (only available on Windows Server).
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Credentials (protected by DPAPI) Dump via Network Share (via security)
This rule detects attempt to dump DPAPI credentials (Windows Vault, Chrome, RDP, WiFi, Emails, ...) or registry hives via network share via tools like DonPAPI.
HuntRule TeamWindowssecurityHigh30Premium2026-08-30