Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Flags reg.exe or PowerShell registry edits that alter the ms-settings protocol handler open command path.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium288Free2021-12-20Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo
Alerts on sqlcmd.exe running a query targeting the VeeamBackup dbo Credentials table to dump sensitive credentials.
frack113, Huntrule TeamWindowsprocess_creationHigh373Free2021-12-20Windows: Detect sc.exe Service Creation with DACL Modification (sdset DCLCWPDTSD)
Alerts on sc.exe sdset usage with DCLCWPDTSD, suggesting permission changes to hide or impede service removal.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh90Free2021-12-20Windows reg.exe Credential Enumeration via Registry Query (HKLM/HKCU)
Flags reg.exe registry queries (REG_SZ, recursive) focused on HKLM/HKCU and PuTTY Sessions to enumerate credential material.
frack113, Huntrule TeamWindowsprocess_creationMedium2010Free2021-12-20PowerShell Credential Manager enumeration via vaultcmd /listcreds
Flags PowerShell using vaultcmd /listcreds to enumerate Windows/Web credential manager stored entries.
frack113, Huntrule TeamWindowsps_scriptMedium133Free2021-12-20PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)
Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.
frack113, Huntrule TeamWindowsps_scriptMedium4310Free2021-12-20PowerShell Credential Discovery via Recursive File Search and Select-String
Flags PowerShell script blocks that recursively list files and run select-string pattern searches, indicative of credential hunting.
frack113, Huntrule TeamWindowsps_scriptMedium164Free2021-12-19Windows: Process Execution of PsLogList with Event Log Dump/Export Flags
Detects PsLogList executions aimed at Security/Application/System logs with dump/export/clear command-line switches.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium193Free2021-12-18Windows CleanWipe-Like PUA Execution via System Tool Uninstall Switches
Flags Windows processes launching CleanWipe-like removal tools with uninstall parameters for security impairment investigation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh259Free2021-12-18Windows Process Creation: Advanced Port Scanner PUA Execution via /portable /lng
Flags Windows launches of Advanced Port Scanner with /portable and /lng parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2021-12-18Windows Process Command-Line Flags Indicating Auditpol Policy Tampering
Detects auditpol runs with flags that disable key audit categories, indicating potential audit policy tampering for defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh192Free2021-12-18Windows: java.exe Parent Spawning cmd/powershell/bash Processes
Alerts when java.exe launches cmd, PowerShell, or bash on Windows, a potential sign of command execution.
Andreas Hunkeler (@Karneades), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium80Free2021-12-17Windows: Alert on Java.exe Spawning Suspicious System and Script Binaries
Triggers when java.exe launches a child utility commonly abused for command execution and administration.
Andreas Hunkeler (@Karneades), Florian Roth, Huntrule TeamWindowsprocess_creationHigh100Free2021-12-17Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
frack113, Huntrule TeamWindowsprocess_creationHigh413Free2021-12-16PowerShell Security Software Discovery Using get-process Piped to where-object (Windows)
Flags PowerShell scripts that enumerate processes and filter results for security software by vendor/product keywords.
frack113, Anish Bogati, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium191Free2021-12-16