Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
AnyDesk Executable Execution on Windows
Detects AnyDesk-related process launches on Windows by matching executable names and AnyDesk product metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium70Free2022-02-11Windows File Creation Indicators for Local SAM Database Exports
Alerts on Windows file creations with filenames indicative of a local SAM export or backup artifact.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh198Free2022-02-11Windows Recent Files Shortcut Points to ISO/IMG/VHD Mount Images
Flags Windows Recent Items entries that reference ISO/IMG/VHD/VHDX mount shortcuts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventMedium143Free2022-02-11Windows File Events: AnyDesk user.conf and system.conf Temporary Artefacts
Identifies Windows file writes of AnyDesk user.conf or system.conf in AppData\Roaming.
frack113, Huntrule TeamWindowsfile_eventMedium101Free2022-02-11Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Alerts on command lines using TrolleyExpress.exe PID parameters consistent with LSASS memory dumping on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-02-10Windows LSASS memory access from TrolleyExpress/ProcessDump/dump64 processes
Alerts on Windows processes attempting to access lsass.exe from TrolleyExpress.exe, ProcessDump.exe, or dump64.exe with dump-like access rights.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh141Free2022-02-10Windows LSASS Memory Access Triggered by Source Image Containing 'dump' Keyword
Alerts when a process named with 'dump' requests specific access rights to lsass.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh70Free2022-02-10Windows Script Interpreter Execution From Suspicious Folders via Command-Line Flags
Flags-and-location-based detection of cscript/wscript/mshta-style script execution launched from TEMP/Public/user directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh348Free2022-02-08Windows Process Command Line Network Recon via nslookup LDAP SRV Query
Identifies Windows command lines running nslookup with an LDAP SRV domain controller discovery query string.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-02-07Windows Process Creation: cmd.exe Launching with PowerShell in .lnk Link Command
Alerts when explorer launches cmd.exe with command lines containing both PowerShell and a .lnk reference.
frack113, Huntrule TeamWindowsprocess_creationMedium141Free2022-02-06Windows PowerShell: DSInternals Get-ADReplAccount Enumeration
Alerts on PowerShell execution of Get-ADReplAccount with -All and -Server parameters for AD replication account enumeration.
frack113, Huntrule TeamWindowsps_scriptMedium172Free2022-02-06Windows Registry ServiceDll Hijack via Service Parameters\ServiceDll
Alerts on ServiceDll value changes for Windows services in the registry, indicating potential DLL load persistence.
frack113, Huntrule TeamWindowsregistry_setMedium141Free2022-02-04Windows NTLM brute force targeting workstation/device names
Alerts on NTLM EventID 8004 when WorkstationName equals common spoofed client names used in brute force attempts.
Jerry Shockley '@jsh0x', Huntrule TeamWindowsntlmMedium365Free2022-02-02Windows PowerShell: Suspicious Unblock-File to Remove Zone.Identifier
Flags PowerShell use of Unblock-File (-Path) that can remove Zone.Identifier downloaded-file metadata.
frack113, Huntrule TeamWindowsps_scriptMedium4510Free2022-02-01PowerShell Mount-DiskImage with -ImagePath to Access Disk Images
Alerts on PowerShell script blocks calling Mount-DiskImage with -ImagePath, indicative of disk-image-based payload staging.
frack113, Huntrule TeamWindowsps_scriptLow342Free2022-02-01