Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server
Flags LsaSrv events 6038/6039 showing NTLMv1 authentication between client and server on Windows.
Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium275Free2022-04-26Windows Sysmon Application Popup Crash (Event ID 26)
Flags Application Popup events reporting sysmon64.exe/sysmon.exe “Application Error” (Event ID 26).
Tim Shelton, Huntrule TeamWindowssystemHigh104Free2022-04-26Windows msiexec.exe Command Line Loading a DLL and Calling DllUnregisterServer
Alert when msiexec.exe runs with -z and a .dll on the command line, consistent with DLL DllUnregisterServer execution.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2022-04-24PowerShell WMI Win32_Product MSI Installation via Invoke-CimMethod
Flags PowerShell using WMI Win32_Product via Invoke-CimMethod to invoke an MSI install.
frack113, Huntrule TeamWindowsps_scriptMedium91Free2022-04-24Windows: File Creation of Get-Variable.exe in PowerShell WindowsApps Path
Alerts on creation of Get-Variable.exe in Local\Microsoft\WindowsApps, a potential cmdlet-path hijack.
frack113, Huntrule TeamWindowsfile_eventHigh162Free2022-04-23Windows Remote Thread Created in KeePass.exe
Flags remote thread creation targeting KeePass.exe, a possible indicator of credential theft.
Timon Hackenjos, Huntrule TeamWindowscreate_remote_threadHigh93Free2022-04-22Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Alerts on rundll32 launching the Windows Key Manager (keymgr / KRShowKeyMgr), a potential credential access step.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-04-21Windows process contacting Dropbox API from non-Dropbox executables
Alerts when a non-Dropbox executable makes initiated connections to Dropbox API endpoints on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh91Free2022-04-20Windows Process Creation: msiexec.exe Embedding Spawned by PowerShell/cmd/pwsh
Alerts when cmd/powershell launches msiexec.exe with -Embedding, a proxy execution pattern.
frack113, Huntrule TeamWindowsprocess_creationMedium102Free2022-04-16Windows Registry: Delete SD Value Under Schedule\TaskCache\Tree to Impair Scheduled Task Visibility
Detects deletion of the SD registry value under Schedule\TaskCache\Tree, which can impair scheduled task visibility.
Sittikorn S, Huntrule TeamWindowsregistry_deleteMedium142Free2022-04-15Windows schtasks.exe scheduled task creation from suspicious folders
Alerts on schtasks.exe /create using PowerShell/cmd and suspicious folder paths like ProgramData.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh404Free2022-04-15Windows Network Connections Initiated by Eqnedt32.EXE
Identifies outbound network connections started by eqnedt32.exe on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh132Free2022-04-14PowerShell Hyper-V Cmdlets Execution via Script Blocks (New-VM, Set-VMFirmware, Start-VM)
Alerts when PowerShell script blocks use Hyper-V VM creation or start cmdlets (New-VM, Set-VMFirmware, Start-VM).
frack113, Huntrule TeamWindowsps_scriptMedium122Free2022-04-09Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Flags VaultCmd.exe executions that enumerate saved Windows Credential Manager entries using /listcreds.
frack113, Huntrule TeamWindowsprocess_creationMedium141Free2022-04-08Windows Process Creation: SQLite Access to Firefox Profile Databases
Alerts when Windows runs SQLite tooling to query Firefox profile DBs like cookies.sqlite or places.sqlite.
frack113, Huntrule TeamWindowsprocess_creationHigh92Free2022-04-08