Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows PowerShell: Query SMB Shares via Get-SmbShare
Alerts on PowerShell script blocks running Get-SmbShare to discover SMB shares.
frack113, Huntrule TeamWindowsps_scriptLow103Free2021-12-15PowerShell ScriptBlock Enumeration of AD Group Membership and User Attributes (Windows)
Flags PowerShell script blocks querying AD group membership and user details for discovery of privileged directory information.
frack113, Huntrule TeamWindowsps_scriptLow371Free2021-12-15PowerShell Module: Get-SmbShare Used for SMB Share Discovery
Detects PowerShell module usage of Get-SmbShare to enumerate SMB shares across networked systems.
frack113, Huntrule TeamWindowsps_moduleLow475Free2021-12-15PowerShell module enumeration of AD principals via get-ADPrincipalGroupMembership
Flags PowerShell module usage of Get-ADPrincipalGroupMembership and Get-ADUser with -pr -f patterns indicative of AD discovery.
frack113, Huntrule TeamWindowsps_moduleLow244Free2021-12-15Windows process execution of where.exe with browser bookmark database or history artifacts
Alerts on where.exe executions referencing browser history/bookmarks/cookie database artifacts in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow132Free2021-12-13Windows: Delete Backup or System State Backups via wbadmin.exe
Flags wbadmin.exe command lines that delete backup or system state backups, potentially impacting recovery.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium141Free2021-12-13Windows wbadmin.exe Deletes All Backup Copies (keepVersions:0)
Flags wbadmin.exe executions that delete all backups/system state backups using keepVersions:0.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh183Free2021-12-13Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
frack113, Huntrule TeamWindowsprocess_creationHigh255Free2021-12-13Windows CMD dir /S File and Subfolder Enumeration
Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.
frack113, Huntrule TeamWindowsprocess_creationLow131Free2021-12-13PowerShell Script Block Collection of Browser Bookmarks via Get-ChildItem
Detects PowerShell Get-ChildItem activity used to recursively enumerate browser bookmarks from a target path.
frack113, Huntrule TeamWindowsps_scriptLow182Free2021-12-13Windows Process Discovery via wmic.exe "group" Flag
Flags wmic.exe process executions querying local group information via a "group" command-line argument.
frack113, Huntrule TeamWindowsprocess_creationLow348Free2021-12-12PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
frack113, Huntrule TeamWindowsps_scriptLow329Free2021-12-12PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
frack113, Huntrule TeamWindowsps_moduleLow131Free2021-12-12Windows Process Creation: Nmap/Zenmap (nmap.exe or zennmap.exe) Execution
Flags Windows execution of Nmap/Zenmap (nmap.exe or zennmap.exe) used for remote service discovery.
frack113, Huntrule TeamWindowsprocess_creationMedium171Free2021-12-10Windows Net.exe Network Connections Discovery via Use Sessions Query
Flags net.exe/net1.exe commands using 'use sessions' to enumerate network connection/session information.
frack113, Huntrule TeamWindowsprocess_creationLow150Free2021-12-10