Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Credential Manager Vault/File Access by Uncommon Application Images
Alerts on access to Windows credential/vault files by uncommon processes based on image path and file location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium111Free2022-10-11Windows Process Hacker Execution Identified by Image Metadata and Hashes
Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium132Free2022-10-10Windows PowerShell Recon Using Get-LocalGroupMember on Local/Well-Known Groups
Flags PowerShell Get-LocalGroupMember usage targeting notable local group names in process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium175Free2022-10-10Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh113Free2022-10-10Windows: NPS (npc.exe) Port Forwarding Proxy Execution via Command-Line Parameters
Flags Windows executions of npc.exe with NPS server, vkey/password, or config=npc command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh465Free2022-10-08Windows Execution of IOX (iex/port forwarding) Tunnel/Proxy Tool via Process Creation
Alerts on Windows process creation for iox.exe with tunneling/proxy forwarding command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2022-10-08Windows Process Creation: SharpWSUS or WSUSpendu Execution via PowerShell Parameters
Detects command-line execution patterns for SharpWSUS or WSUSpendu on Windows.
"@Kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh246Free2022-10-07Windows LPE Attempt via TabTip CLSID Using Microsoft-Windows-DistributedCOM (Event ID 10001)
Alerts when TabTip.exe is started via CLSID/DCOM activation in Windows DistributedCOM EventID 10001.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh61Free2022-10-07Windows Process Creation: GMER Rootkit Tool Execution (gmer.exe)
Flags execution of gmer.exe on Windows when matched by known process hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-10-05PowerShell PSAsyncShell Reverse Shell Activity via Script Block Logging
Detects PowerShell use of PSAsyncShell by matching the tool name in logged script block text.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh121Free2022-10-04Windows Driver Load of Known Vulnerable Drivers by File Name
Alerts when Windows loads a driver whose filename matches a list of known vulnerable drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadLow133Free2022-10-03Windows Malicious Driver Load Identified by Known Bad Driver File Names
Alerts when Windows loads a driver whose file name matches a curated list of known malicious/suspicious drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadMedium152Free2022-10-03Windows Registry: Disable Privacy Settings Experience via DisablePrivacyExperience Policy
Flags Windows registry policy changes that disable the Privacy Settings Experience by setting DisablePrivacyExperience to 0x00000000.
frack113, Huntrule TeamWindowsregistry_setMedium151Free2022-10-02Windows: Process creation of UltraVNC VNCViewer (VNCViewer.exe)
Flags execution of UltraVNC VNCViewer.exe on Windows based on process creation metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium254Free2022-10-02Windows Registry: Modify User Shell Folders Startup Values for Persistence
Alerts on Windows Registry changes to User Shell Folders startup-related values that may be used to establish persistence.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh393Free2022-10-01