Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-06-27Windows: Potential Process Injection via Msra.exe Spawning Suspicious Child Processes
Flags Msra.exe spawning suspicious tools that may indicate process injection or post-exploitation activity on Windows.
Alexander McDonald, Huntrule TeamWindowsprocess_creationHigh162Free2022-06-24Windows DNS Queries Containing ufile.io Domain
Alerts on Windows DNS lookups where the queried name contains ufile.io, indicating potential exfiltration-related activity.
yatinwad, TheDFIRReport, Huntrule TeamWindowsdns_queryLow90Free2022-06-23Windows Process Execution: msdt.exe Launched with -cab Flag
Alerts when msdt.exe is started with the "-cab" argument, consistent with suspicious cabinet-based diagcab usage.
Nasreddine Bencherchali (Nextron Systems), GossiTheDog, frack113, Huntrule TeamWindowsprocess_creationMedium121Free2022-06-21Windows PowerShell: Execution of TroubleshootingPack Cmdlets (msdt-related usage)
Flags PowerShell script blocks invoking TroubleshootingPack with unattended answer-file arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium143Free2022-06-21Windows PowerShell Hotfix Enumeration via Win32_QuickFixEngineering
Detects PowerShell scripts enumerating installed hotfixes by querying Win32_QuickFixEngineering for HotFixID.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium211Free2022-06-21Windows wmic.exe Used to Start or Stop Services
Alerts on wmic.exe command lines invoking startservice or stopservice via service calls.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2022-06-20Windows WMIC Process Creation Recon for Unquoted Service Paths
Flags wmic.exe service queries requesting name/displayname/pathname/startmode to support unquoted service path reconnaissance.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium161Free2022-06-20Windows Hotfix Inventory Recon via wmic.exe qfe
Detects wmic.exe executions with "qfe" used to enumerate installed Windows hotfixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium147Free2022-06-20Windows CLI Enumeration of 3rd-Party Credential Registry Keys
Alerts when Windows processes use command-line queries to enumerate credential-containing third-party registry keys.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium459Free2022-06-20Windows Dsacls.EXE Password Spraying Check via /user and /passwd
Flags dsacls.exe executions that specify both /user: and /passwd:, consistent with password spraying attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium1810Free2022-06-20Windows: dsacls.exe used to grant potentially over-permissive access rights
Alerts on dsacls.exe commands using /G to grant wide or permissive ACL permissions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium152Free2022-06-20PowerShell WMI Service Enumeration for Unquoted Service Path Recon
Flags PowerShell WMI queries for Win32_Service fields to enumerate potential unquoted service path issues.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium82Free2022-06-20Windows Registry: New W32Time TimeProvider DllName Values Set Under Services\W32Time\TimeProvider
Alerts on new or changed W32Time TimeProvider DllName registry values under Services\W32Time\TimeProvider.
frack113, Huntrule TeamWindowsregistry_setHigh132Free2022-06-19Windows: Chromium-Based Browser Launched via Script Host with --load-extension
Flags Windows process creation where Chromium browsers are spawned with --load-extension= from common script/LOLBins parents.
Aedan Russell, frack113, X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh100Free2022-06-19