Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Creation: NirCmd Command Execution
Alerts when NirCmd.exe is launched with command-execution-oriented parameters in the process command line.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium191Free2022-01-24Windows InstallUtil Execution Suspiciously Omitting /logfile Output
Alert when InstallUtil.exe runs from .NET Framework with logging parameters indicating output suppression.
frack113, Huntrule TeamWindowsprocess_creationMedium123Free2022-01-23Windows PowerShell Scripts Testing Uncommon Port Connectivity via Test-NetConnection
Detects PowerShell scripts using Test-NetConnection to reach a target on non-443/80 ports.
frack113, Huntrule TeamWindowsps_scriptMedium111Free2022-01-23Windows PowerShell: Suspicious SslStream Client Certificate Validation in Script Block
Flags PowerShell scripts referencing SslStream and client-side certificate validation during SSL client authentication.
frack113, Huntrule TeamWindowsps_scriptLow143Free2022-01-23Windows PowerShell: WebRequest User-Agent Modification in ScriptBlockText
Detects PowerShell scripts that make web requests and set a custom -UserAgent value.
frack113, Huntrule TeamWindowsps_scriptMedium142Free2022-01-23Windows Office Macro File Creation Triggered by Script/LOLBin Parent Process
Alerts when macro-enabled Office files are created by common Windows script execution processes.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh153Free2022-01-23Windows Office Macro File Creation from Browser or Email Client
Flags Windows creation of macro-enabled Office files (.docm/.xlsm/.pptm) initiated by common browsers or email clients.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow187Free2022-01-23Windows Office Macro File Creation via Office Applications
Alerts on creation of macro-enabled Office documents/templates by Office apps on Windows, excluding Office temporary files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow161Free2022-01-23Windows Registry: Internet Settings Zone and Cache-related Key Modifications
Flags registry writes to Windows Internet Settings-related keys that can be abused to alter zone trust or store persistence data.
frack113, Huntrule TeamWindowsregistry_setLow133Free2022-01-22Windows Registry Set to Hide File Extensions via Explorer Advanced Keys
Flags registry changes under Explorer Advanced that hide file extensions by setting specific DWORD values.
frack113, Huntrule TeamWindowsregistry_setMedium178Free2022-01-22Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Flags Windows registry changes to IE ZoneMap domain entries that alter security zone assignments for targeted domains.
frack113, Huntrule TeamWindowsregistry_setMedium2910Free2022-01-22Radmin Viewer Utility Execution on Windows (Process Creation)
Alerts when Radmin Viewer (Radmin.exe) is launched, based on process metadata in Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationMedium225Free2022-01-22Windows Network Connection Initiated by IMEWDBLD.EXE
Alerts when IMEWDBLD.EXE initiates a network connection on Windows.
frack113, Huntrule TeamWindowsnetwork_connectionHigh151Free2022-01-22Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color
Alerts on colorcpl.exe creating files in C:\Windows\System32\spool\drivers\color\ with suspicious target filenames.
frack113, Huntrule TeamWindowsfile_eventHigh166Free2022-01-21Windows Kerberoasting Initial Query: Successful 4769 RC4 Service Requests with Filters
Collects successful Windows 4769 RC4 service-ticket requests while excluding krbtgt and computer/service account patterns for kerberoasting triage.
"@kostastsale, Huntrule Team"WindowssecurityMedium343Free2022-01-21