Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
PowerShell Script Block Logging: Suspicious Windows Event Log Clearing Cmdlets
Flags PowerShell script blocks that call event log clearing cmdlets or ClearLog to impair Windows log visibility.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium92Free2022-09-12PowerShell Enable-WindowsOptionalFeature Enables Suspicious Windows Optional Features (Windows)
Alerts on PowerShell enabling Windows optional features online for specific, potentially risky feature names.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2022-09-10PowerShell Disable-WindowsOptionalFeature -Online -FeatureName for Windows Defender features
Detects PowerShell disabling online Windows Defender features via Disable-WindowsOptionalFeature -FeatureName.
frack113, Huntrule TeamWindowsps_scriptHigh411Free2022-09-10Windows Registry Winlogon AllowMultipleTSSessions Enabled
Alerts on enabling Winlogon AllowMultipleTSSessions (DWORD 0x00000001), allowing concurrent RDP sessions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium82Free2022-09-09Windows Process Creation Recon via Event Log Query Tools and Event ID Searches
Flags Windows processes running event log query utilities and commands that search specific event IDs or dump log content.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium221Free2022-09-09Windows Schtasks.exe Scheduled Task Creation or Modification with Suspicious Schedule Types
Alerts on schtasks.exe commands that schedule tasks using ONLOGON/ONSTART/ONCE/ONIDLE with potentially malicious privilege context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh204Free2022-09-09Windows schtasks Delete All Scheduled Tasks via /tn * /delete /f
Flags schtasks.exe commands that forcibly delete all scheduled tasks on the local host using /delete /tn * /f.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-09Windows schtasks.exe Used to Delete Scheduled Tasks for System and Security Components
Alerts when schtasks.exe runs with /delete targeting sensitive Windows scheduled tasks that support security, updates, or recovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4210Free2022-09-09Windows vmnat.exe Renamed Execution for Possible DLL Side-Loading
Alerts on Windows processes where vmnat.exe appears renamed, which may support stealthy execution and DLL side-loading behavior.
elhoim, Huntrule TeamWindowsprocess_creationHigh103Free2022-09-09PowerShell User Discovery and Export with Get-ADUser
Flags PowerShell Get-ADUser enumeration (filter *) followed by exporting results to a file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium481Free2022-09-09Windows Root Certificate Installation from Suspicious Paths via PowerShell Import-Certificate
Alerts on PowerShell importing a root certificate into Cert:\LocalMachine\Root from suspicious file paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-09-09PowerShell Email Address Exfiltration via EXIF-style Recipient Harvesting on Windows
Alerts when PowerShell command lines enumerate Exchange recipients and expand email address properties, indicating potential email data exfiltration.
Nasreddine Bencherchali (Nextron Systems), Azure-Sentinel (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-09Windows node.exe Execution with -e/--eval and suspicious child process usage
Alerts on node.exe started with -e/--eval and command-line indicators of child_process and net.socket connect activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh182Free2022-09-09Windows Security: Suspicious SAMTHEADMIN-* Computer/Account Names Ending with $
Alerts on Windows Security events with computer account names starting SAMTHEADMIN- and ending with $.
elhoim, Huntrule TeamWindowssecurityCritical171Free2022-09-09Windows WMIC System Reconnaissance Using "computersystem" Flag
Flags wmic.exe runs that include the "computersystem" argument for Windows host information discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium92Free2022-09-08