Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows PowerShell nslookup DNS TXT Download Cradle
Identifies PowerShell launching an nslookup-based cradle that queries TXT records with HTTP-related nslookup parameters.
Sai Prashanth Pulisetti @pulisettis, Aishwarya Singam, Huntrule TeamWindowsps_classic_startMedium357Free2022-12-10Windows ETW Logging Disabled via SCM Registry TracingDisabled Key
Detects SCM ETW logging being disabled by setting the TracingDisabled registry DWORD for services.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow152Free2022-12-09Windows Registry Change Disables ETW for rpcrt4.dll via ExtErrorInformation
Flags Windows registry updates that disable ETW logging for rpcrt4.dll through ExtErrorInformation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow325Free2022-12-09Windows Process Creation: conhost.exe with High IntegrityLevel and -ForceV1
Flags conhost.exe started with -ForceV1 from a High integrity process on Windows.
frack113, Huntrule TeamWindowsprocess_creationInformational143Free2022-12-09Windows Image Load of Specific System DLLs Not Normally Present in System Directories
Alerts on image load events for specific system-path DLLs with unexpected “phantom” DLL names on Windows.
Nasreddine Bencherchali (Nextron Systems), SBousseaden, Huntrule TeamWindowsimage_loadHigh131Free2022-12-09Windows Registry: LSASS Full Dump via WER LocalDumps DumpType=2
Flags registry changes enabling LSASS full memory dumps by setting WER LocalDumps DumpType to 0x2.
"@pbssubhash, Huntrule Team"Windowsregistry_setHigh252Free2022-12-08Windows: LSASS Dump (.dmp) Files in CrashDumps Folder
Alerts when an lsass.exe dump (.dmp) appears in the Windows CrashDumps directory under systemprofile.
"@pbssubhash, Huntrule Team"Windowsfile_eventHigh399Free2022-12-08Windows Application Error: LSASS (lsass.exe) Crashed (Event ID 1000)
Alerts on Application Error (Event ID 1000) entries where lsass.exe crashes, using Windows Application event telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh2010Free2022-12-07Windows windefend alerts on suspicious Windows Defender configuration changes (Disable* and SpyNet reporting)
Alerts on windefend Event 5007 when Defender configuration changes set features like anti-spyware, scanning, or SpyNet reporting to disabled values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh286Free2022-12-06Windows Windefend: Defender Restored File from Quarantine (EventID 1009)
Alerts on Windows Defender Windefend events indicating an item was restored from quarantine (Event ID 1009).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh91Free2022-12-06Windows Defender SubmitSamplesConsent Disabled (Real-Time Protection)
Flags Windows Defender configuration changes disabling automatic sample submission (SubmitSamplesConsent=0x0).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendLow349Free2022-12-06Windows Process Creation: Command Line Contains Emoji Characters
Alerts on Windows process executions whose command line includes emoji/symbol characters from a predefined list.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh2810Free2022-12-05Windows Process Command Line Contains Emoji Characters
Alerts when a Windows process command line includes emoji characters, which can be used to obscure activity or bypass naive detections.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh141Free2022-12-05Windows Process Creation: Command Line Contains Specific Emoji Characters
Alerts when a Windows process command line includes specific emoji Unicode characters that may be used for evasion or obfuscation.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh225Free2022-12-05Windows Process Creation Command-Line Contains Emoji Characters
Alerts on Windows executions whose command line includes emoji Unicode characters.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh319Free2022-12-05