Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Detects AdvancedRun execution where /RunAs is set to specific high-privilege IDs in the process command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-01-20Windows PUA AdvancedRun.exe Execution
Detects AdvancedRun.exe executions on Windows with /Run and /RunAs style command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-01-20Windows Code Integrity: Unmet Signing Level Requirements When Loading a File (Event ID 3033/3034)
Alerts on Code Integrity file-load attempts failing signing level requirements, based on Event ID 3033/3034 in Windows Code Integrity logs.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalLow162Free2022-01-20Windows PowerShell XML Document Load Used for Execution
Flags PowerShell script blocks that use XML document loading combined with expression/command execution keywords.
frack113, Huntrule TeamWindowsps_scriptMedium3810Free2022-01-19PowerShell MsXml2.XmlHttp COM Object Instantiation
Alerts on PowerShell creating an MsXml2.XmlHttp COM object through New-Object -ComObject.
frack113, MatilJ, Huntrule TeamWindowsps_scriptMedium142Free2022-01-19Windows Registry: Disable Administrative Share Creation via LanmanServer Parameters
Flags registry writes that disable Windows administrative share auto-creation under LanmanServer parameters.
frack113, Huntrule TeamWindowsregistry_setMedium151Free2022-01-16Windows msiexec.exe Quiet MSI Installation with Installer Arguments
Flags msiexec.exe launched with -q plus MSI installer switches, indicating quiet installation behavior in Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationMedium70Free2022-01-16Windows: Suspicious msiexec.exe Command-Line Writes Install Logs with /Y
Alerts on suspicious msiexec.exe executions using the /Y argument that are not consistent with common installer locations.
frack113, Huntrule TeamWindowsprocess_creationMedium437Free2022-01-16Windows DISM Online Disable-Feature via DismHost.exe or Dism.exe
Flags Windows DISM/DismHost executions using /Online and /Disable-Feature, a common defense-impairment technique.
frack113, Huntrule TeamWindowsprocess_creationMedium144Free2022-01-16PowerShell ScriptBlock Logging: Set-MpPreference disables Windows Defender scanning or allows threats
Alert on PowerShell Set-MpPreference usage that disables Defender scanning/monitoring or sets threat default actions to Allow.
frack113, elhoim, Tim Shelton (fps, alias support), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh342Free2022-01-16Windows: Deletion of TeamViewer log files
Alerts on deletion of TeamViewer *.log files on Windows, excluding deletions performed by svchost.exe.
frack113, Huntrule TeamWindowsfile_deleteLow161Free2022-01-16Windows rmdir Directory Removal via cmd.exe Execution
Monitors cmd.exe process creation where rmdir is used with /s and/or /q to delete directories and reduce forensic artifacts.
frack113, Huntrule TeamWindowsprocess_creationLow80Free2022-01-15Windows del/erase Command-Line File Deletion via cmd.exe
Flags cmd.exe executions running del/erase for file removal, including common flags like /f, /s, and /q.
frack113, Huntrule TeamWindowsprocess_creationLow229Free2022-01-15Windows PowerShell: Start-Process with -PassThru and -FilePath
Alerts on PowerShell Start-Process calls that include -PassThru and -FilePath, based on ScriptBlockText matches.
frack113, Huntrule TeamWindowsps_scriptMedium151Free2022-01-15Windows rundll32 Execution With Uncommon DLL/CPL/INF Extension in Command Line
Alerts on Windows rundll32 executions whose command lines lack common .cpl/.dll/.inf endings, indicating potential unusual invocation.
Tim Shelton, Florian Roth (Nextron Systems), Yassine Oukessou, Huntrule TeamWindowsprocess_creationMedium4110Free2022-01-13