Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
PowerShell AD Account Creation Library Usage via AccountManagement Namespace on Windows
Alert on PowerShell Script Block content referencing System.DirectoryServices.AccountManagement, indicating potential AD principal manipulation.
frack113, Huntrule TeamWindowsps_scriptMedium311Free2021-12-28PowerShell Scheduled Task Creation via ScriptBlock Logging
Identifies PowerShell script blocks that create and register scheduled tasks using TaskScheduler cmdlets or CIM WMI method calls.
frack113, Huntrule TeamWindowsps_scriptMedium92Free2021-12-28Windows PowerShell Screen Capture via CopyFromScreen
Flags PowerShell scripts containing .CopyFromScreen, indicative of desktop screen capture activity.
frack113, Huntrule TeamWindowsps_scriptMedium101Free2021-12-28Windows Suspicious File Downloads from Outlook/OneNote Attachment Domains via Command-Line
Flags Windows command-line downloads using curl/wget or PowerShell from Outlook/OneNote attachment domains.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2021-12-27Windows Process Execution of Hashcat.exe for Password Cracking
Alerts on Hashcat.exe launched with cracking-focused flags targeting an offline SAM-derived dataset.
frack113, Huntrule TeamWindowsprocess_creationHigh409Free2021-12-27Windows: Findstr searches GPP cpassword in SYSVOL XML
Alerts when Windows findstr/find searches SYSVOL XML files for GPP cpassword.
frack113, Huntrule TeamWindowsprocess_creationHigh417Free2021-12-27Windows PowerShell Credential Guessing via LDAP using System.Net.NetworkCredential
Detects PowerShell scripts referencing LDAP connection and .NET network credential handling, potentially indicating remote credential access activity.
frack113, Huntrule TeamWindowsps_scriptLow171Free2021-12-27Windows PowerShell Copies a DLL into System32 or SysWOW64
Flags PowerShell Copy-Item targeting Windows\System32 or Windows\SysWOW64 for file placement.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2021-12-27Windows schtasks.exe /disable Used to Disable Security-Critical Scheduled Tasks
Flags schtasks.exe executions using /disable against security-critical Windows scheduled task paths.
frack113, Nasreddine Bencherchali (Nextron Systems), X__Junior, Huntrule TeamWindowsprocess_creationHigh101Free2021-12-26Windows: cipher.exe Overwrites Deleted Data Using /w
Flags Windows cipher.exe runs with /w: to overwrite deleted data on disk.
frack113, Huntrule TeamWindowsprocess_creationMedium345Free2021-12-26Windows PowerShell Wallpaper Replacement via Registry and SystemParametersInfo
Identifies PowerShell script blocks that modify the HKCU Desktop\WallPaper setting to replace a user’s wallpaper.
frack113, Huntrule TeamWindowsps_scriptLow332Free2021-12-26Windows PowerShell Script: Remove Account From Domain Admin Group via Remove-ADGroupMember
Alerts on PowerShell commands removing specified members via Remove-ADGroupMember, potentially disrupting Domain Admin access.
frack113, Huntrule TeamWindowsps_scriptMedium151Free2021-12-26Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh100Free2021-12-22Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Alerts on Windows process executions using filenames that match common Sysinternals tools to indicate potential binary impersonation.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2021-12-20Suspicious Windows Process Creation as SYSTEM User with Likely Credential/Defense Evasion Commands
Flags SYSTEM-context process executions on Windows that include suspicious tool names or command-line patterns such as PowerShell/Mimikatz indicators.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindowsprocess_creationHigh162Free2021-12-20