Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry: Exploit Guard ProtectedFolders Value Deleted
Alerts on deletion of registry values under Exploit Guard Controlled Folder Access ProtectedFolders.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh121Free2022-08-05Windows Process Creation: wusa.exe Cab Extraction From Suspicious Directory Paths
Flags wusa.exe with /extract: originating from common temp/public paths, a potential CAB-based payload unpacking behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-08-05Windows Process Command Line Contains NTFS 8.3 Short Filename Patterns (~1/~2.*)
Detects Windows command lines referencing NTFS 8.3 short names like ~1.exe or ~2.ps1.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium151Free2022-08-05Windows Process Creation: Remove-MpPreference Used to Tamper Windows Defender Settings
Flags process executions that call Remove-MpPreference with Defender tampering-related parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-08-05Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh446Free2022-08-05Windows Suspicious File Creation in AppData Outside Common Subdirectories
Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh82Free2022-08-05Windows Defender Exploit Guard Tamper via Controlled Folder Access AllowedApplications or ProtectedFolders Changes
Alerts on Windefend EventID 5007 when Exploit Guard ProtectedFolders or AllowedApplications lists are modified.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh103Free2022-08-05Windows RDP Tunneling Using plink.exe on Local Port 3389
Alert on plink.exe command lines referencing 127.0.0.1:3389 or port 3389, suggesting potential RDP tunneling on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-08-04Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
Florian Roth (Nextron Systems), Microsoft (idea), Huntrule TeamWindowsprocess_creationHigh90Free2022-08-04Windows PsExec Named Pipe Creation from Suspicious Paths (PSEXESVC)
Alerts on PsExec pipe \PSEXESVC creation when the executing image path is in public/temp/desktop/downloads locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdMedium322Free2022-08-04Windows CLI usage of obfuscated IP address patterns in ping/arp commands
Alerts when ping or arp command lines include obfuscated/encoded IP address indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-08-03Windows Process Creation: Obfuscated IP Address in Download Command URLs
Alerts on Windows download commands that include obfuscated/encoded IP addresses in the URL.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-08-03Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical407Free2022-08-03Windows Security Mitigations: Unsigned DLL Blocked from User-Writable Paths
Alerts on blocked unsigned DLL loads targeting public, downloads, desktop, or temp directories in Windows Security Mitigations logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurity-mitigationsHigh132Free2022-08-03Windows Security: DiagTrackEoP POC Default UserName Login Attempt (LogonType 9)
Alerts on Windows 4624 LogonType 9 events targeting a known DiagTrackEoP default username.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityCritical130Free2022-08-03