Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Scheduled Task Creation with Schtasks -XML Using Non-.xml File
Alerts when schtasks.exe creates a scheduled task using -XML but the referenced file does not end with .xml.
Swachchhanda Shrawan Poudel, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium292Free2023-04-20Windows RDP client Mstsc.EXE launched from uncommon browser or email parent process
Alerts when mstsc.exe is spawned by a browser or Outlook, suggesting potential RDP access using a local .rdp file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2023-04-18Windows mstsc.exe launched with a local .rdp file from suspicious paths
Alerts on mstsc.exe executions that use a local .rdp file referenced from suspicious command-line paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-04-18Windows mstsc.exe launched with local .rdp file argument
Alerts on mstsc.exe executions that reference local .rdp files via the command line.
Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock, Huntrule TeamWindowsprocess_creationLow332Free2023-04-18Windows: Uncommon Process Creates .rdp Remote Desktop File
Alerts on creation of .rdp files by processes that are not typically associated with producing them on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-04-18Windows winget Install from Zone.Identifier/WinGet Temp Contents Marked by Zone Transfer
Alerts on winget staging under Temp\WinGet combined with ZoneTransfer ZoneId=3 and Zone.Identifier ADS contents.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh152Free2023-04-18Windows Registry: Winget EnableLocalManifestFiles Set to DWORD 1
Flags setting the Winget AppInstaller local manifest installation policy (EnableLocalManifestFiles) to enabled.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium151Free2023-04-17Windows winget AppInstaller admin_settings registry modification via winget.exe
Detects winget.exe-driven changes to AppInstaller admin_settings in the registry under LocalState\admin_settings.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow413Free2023-04-17Windows Process: winget adds new download source via 'source add' with IP/endpoint
Alerts on winget.exe being used to add a new package download source specified by an IP address.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-04-17Windows Winget adds HTTP package source
Alerts when winget is used to add a package source pointing to an http:// URL.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-04-17Windows: winget.exe adds new download sources via 'source add'
Alerts on winget.exe usage to add new package download sources using 'source add'.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-04-17Windows Process Creation: Crassus Privilege Escalation Discovery Tool Execution
Identifies execution of the Crassus Windows privilege escalation discovery tool via process metadata.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh278Free2023-04-17Windows: Stracciatella.exe Process Execution Identification (SharpPick behavior)
Alerts on Windows process creation for Stracciatella.exe using PE metadata and known SHA256 hashes.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-04-17Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Flags Certipy.exe execution on Windows using PE metadata and Certipy-like AD CS command-line arguments.
pH-T (Nextron Systems), Sittikorn Sangrattanapitak, Huntrule TeamWindowsprocess_creationHigh319Free2023-04-17Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Identifies Windows processes running Certify.exe with AD certificate abuse-oriented command line arguments.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2023-04-17