Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows PowerShell: Suspicious Invoke-Item After Mount-DiskImage
Flags PowerShell that mounts an image, derives a drive letter, then runs content via invoke-item from that mount.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2022-02-01Windows Suspicious takeown.exe Recursive Ownership Change
Alerts when takeown.exe is run with recursive and file/folder targeting, indicating potential defense impairment via ownership changes.
frack113, Huntrule TeamWindowsprocess_creationMedium4610Free2022-01-30Windows PowerShell ScriptBlock Accessing Browser 'Login Data' Files
Flags PowerShell Copy-Item operations targeting browser Login Data credential database paths on Windows.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2022-01-30Windows File Writes of TeamViewer Session Logs
Flags Windows file creation events for TeamViewer session log artifacts like vprint.db and TVNetwork.log.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventMedium285Free2022-01-30Windows DNS Queries for TeamViewer Domains Triggered by Non-TeamViewer Image
Alerts when TeamViewer domains are resolved via DNS by a process whose image name does not include "TeamViewer".
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryMedium454Free2022-01-30Windows: Application Uninstall via WMIC.exe (WMIC call uninstall)
Flags WMIC.exe commands that include "call" and "uninstall," indicating potential application removal on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium171Free2022-01-28Windows: whoami.exe Executed by Privileged Accounts
Flags execution of whoami.exe from privileged-like accounts using Windows process creation events.
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh154Free2022-01-28Windows: Detect XORDump Utility Launch With LSASS Dump and Debug Module Switches
Alerts on xordump.exe spawning with LSASS-targeting and dump-module switches indicative of credential theft.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2022-01-28Windows File Creation of TeamViewer_Desktop.exe During Install
Alerts on Windows when TeamViewer_Desktop.exe is created, indicating potential installation or dropped remote-access binaries.
frack113, Huntrule TeamWindowsfile_eventMedium163Free2022-01-28Windows Installer Application Removed via MsiInstaller Events
Alerts on Windows Installer events indicating an application was removed via MsiInstaller.
frack113, Huntrule TeamWindowsapplicationLow131Free2022-01-28Windows Process Hollowing Suspected via Replaced In-Memory Image
Alerts on Windows events where a process image is replaced in memory, suggesting possible process hollowing.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Sittikorn S, Huntrule TeamWindowsprocess_tamperingMedium379Free2022-01-25Windows LOLBIN Execution From Abnormal Drive (calc, certutil, mshta, regsvr32, rundll32)
Flags Windows LOLBIN execution when process CurrentDirectory is not empty/null and contains C:\, indicating unusual launch context.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Angelo Violetti - SEC Consult '@angelo_violetti', Aaron Herman, Huntrule TeamWindowsprocess_creationMedium132Free2022-01-25Windows: RunXCmd Command-Line Execution with System or TrustedInstaller Accounts
Flags RunXCmd usage on Windows when invoked to execute commands as System or TrustedInstaller.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh172Free2022-01-24Windows Process Execution: NSudo (NSudo.exe/NSudoLC/NSudoLG)
Alerts on NSudo execution on Windows with privilege and integrity/elevation command-line parameters.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh357Free2022-01-24Windows Process Creation: NirCmd runasSystem CommandLine Usage
Alerts on NirCmd being used to run commands as LocalSystem based on the process command line.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh272Free2022-01-24