Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
frack113, Huntrule TeamWindowsps_scriptLow404Free2022-03-17Windows PowerShell Directory Enumeration via Get-ChildItem and Output Redirection
Flags PowerShell directory enumeration patterns using Get-ChildItem, error suppression, and appended output to a file.
frack113, Huntrule TeamWindowsps_scriptMedium215Free2022-03-17Windows PowerShell Active Directory Group Enumeration via Get-AdGroup Cmdlet
Flags PowerShell script blocks that call Get-ADGroup with -Filter to enumerate Active Directory groups.
frack113, Huntrule TeamWindowsps_scriptLow163Free2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
frack113, Huntrule TeamWindowsps_scriptLow357Free2022-03-17PowerShell Get-ADUser Enumeration Using UserAccountControl DONT_REQ_PREAUTH Flag
Flags Get-ADUser PowerShell scripts enumerating accounts by UserAccountControl DONT_REQ_PREAUTH (4194304).
frack113, Huntrule TeamWindowsps_scriptMedium131Free2022-03-17Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh133Free2022-03-16Windows Remote Thread Creation Targeting Uncommon System Image Processes
Alert on Windows remote thread creation events targeting a predefined list of uncommon processes by image path.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_remote_threadMedium181Free2022-03-16Windows schtasks.exe Create Executes File from AppData\Local
Alerts on schtasks.exe creating tasks that run payloads from C:\Users\<user>\AppData\Local.
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh196Free2022-03-15Windows Process Creation: Suspicious for/foreach Scan Loop with nslookup or ping
Alerts on Windows command lines using for/foreach loops that also run nslookup or ping, consistent with host scanning.
frack113, Huntrule TeamWindowsprocess_creationMedium113Free2022-03-12Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh215Free2022-03-12Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh327Free2022-03-11Windows Process Creation: OfflineScannerShell.exe mpclient.dll DLL Sideloading Risk
Detects OfflineScannerShell.exe launched with an unexpected current directory that could enable mpclient.dll sideloading.
frack113, Huntrule TeamWindowsprocess_creationMedium393Free2022-03-06Windows Process Creation: Replace.exe with -a argument
Detects Replace.exe executions that include the -a argument, which may be used for file replacement.
frack113, Huntrule TeamWindowsprocess_creationMedium265Free2022-03-06Windows Suspicious UltraVNC Command Line With Auto-Reconnect Flags
Alerts on UltraVNC execution using -autoreconnect with -connect and -id in the Windows command line.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh151Free2022-03-04