Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Service Control Manager: Mesh Agent Service Installation via Service Creation (7045)
Flags Windows Event ID 7045 service installations that reference MeshAgent.exe or “Mesh Agent”.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium342Free2022-11-28Windows UAC Bypass via Event Viewer RecentViews Path in Process Command Line
Flags Windows processes whose command lines reference Event Viewer RecentViews and use redirection, consistent with UAC bypass techniques.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2022-11-22Windows Registry NGenAssemblyUsageLog Key Tampering via .NET Usage Log Configuration
Alerts on registry modifications to the .NETFramework NGenAssemblyUsageLog key that can disrupt .NET Usage Log creation.
frack113, Huntrule TeamWindowsregistry_setHigh176Free2022-11-18Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Flags secedit.exe command lines used to export or configure Windows security policy.
Janantha Marasinghe, Huntrule TeamWindowsprocess_creationMedium133Free2022-11-18Windows: Suspicious Powercfg Execution Changing Lock/Video Standby Timeout
Detects powercfg.exe commands attempting to change standby/lock-related timeouts on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium82Free2022-11-18Windows: Suspicious Msbuild.exe execution from uncommon parent process
Alerts when Msbuild.exe runs under an unexpected parent process on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium123Free2022-11-17PowerShell Get-ADUser User Discovery and Data Export via File Output
Detects PowerShell Get-ADUser-based user enumeration combined with exporting results to files or output streams.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium91Free2022-11-17PowerShell Get-ADComputer Cmdlet Used for Computer Discovery and File Export
Flags PowerShell Get-ADComputer wildcard enumeration followed by writing exported computer data to a file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium80Free2022-11-17Windows file activity matching CrackMapExec/Impacket-secretsdump credential dumping temp output patterns
Alerts on Windows temp file creations consistent with CrackMapExec or Impacket-secretsdump credential dumping activity.
SecurityAura, Huntrule TeamWindowsfile_eventHigh3010Free2022-11-16Windows Driver Load: Process Hacker (processhacker.sys) Presence
Flags Windows driver loads of Process Hacker’s processhacker.sys using path and known imphash indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh143Free2022-11-16Windows Process Creation: Suspicious RunAs-Like Command-Line Flag Combination
Flags Windows processes with both target-user and target-command flags in the same command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium91Free2022-11-11PowerShell Get-ADComputer Export of Active Directory Computer Data to File (Windows)
Detects PowerShell running Get-ADComputer (* filter) and exporting results to a file via output/content cmdlets.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium90Free2022-11-10Windows: Detect sftp.exe used as a LOLBIN via -D option
Alerts on Windows executions of sftp.exe using the -D flag with a path argument.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium163Free2022-11-10Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Alerts on Windows Code Integrity Event ID 3077 when an image/driver load is blocked for signing-level or policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh151Free2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-11-09