Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
Detects PowerShell Set-Service commands with SecurityDescriptorSddl SDDL patterns that modify Windows service DACLs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh373Free2022-10-18Windows PowerShell Set-Service SDDL Usage to Hide Services
Flags pwsh Set-Service commands that set a SecurityDescriptorSddl to hide a Windows service from other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-10-17PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Flags PowerShell Set-Service calls that set a SecurityDescriptor SDDL (DCLCWPDTSD) to hide services from other utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh132Free2022-10-17Uncommon Applications Access Windows DPAPI Master Key Files
Alerts on unusual process access to Windows DPAPI master key files under Microsoft\Protect.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium141Free2022-10-17Windows Credential History File Access by Uncommon Applications
Alerts on CREDHIST file access from unexpected application images, indicating potential credential history theft.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium295Free2022-10-17Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Alerts on AD attribute changes adding to msDS-KeyCredentialLink via Windows Security EventID 5136, consistent with shadow credential additions.
Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh246Free2022-10-17Windows process execution: wermgr.exe running outside standard system directories
Alerts when wermgr.exe is launched from a non-standard directory on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh424Free2022-10-14Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-10-14Windows Security Logoff Events (Event ID 4634/4647)
Identifies Windows user logoff using Security Event IDs 4634 and 4647.
frack113, Huntrule TeamWindowssecurityInformational204Free2022-10-14Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)
Alerts on Windows Security Event 4649 indicating a Kerberos replay error (KRB_AP_ERR_REPEAT).
frack113, Huntrule TeamWindowssecurityHigh459Free2022-10-14Windows Security Event 6423: Device Installation Blocked by Policy
Alerts when Windows blocks a device installation due to enforced system policy (Event ID 6423).
frack113, Huntrule TeamWindowssecurityMedium102Free2022-10-14Windows Security Event Add/Remove Computer Account (4741/4743)
Alerts on Windows domain computer account create/delete activity via Security event 4741 and 4743.
frack113, Huntrule TeamWindowssecurityLow80Free2022-10-14Windows: ssh.exe RDP tunneling to :3389 via SSH
Alerts on Windows process executions of ssh.exe that reference RDP port :3389 for SSH tunneling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-10-12Port Forwarding via SSH.EXE on Windows
Flags Windows executions of ssh.exe using remote port forwarding (-R) based on process creation command-line content.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3110Free2022-10-12