Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry RDP Terminal Services Sensitive Settings Tampering
Flags Windows registry changes to sensitive RDP/Terminal Services settings such as shadowing, remote assistance, security, and InitialProgram.
Samir Bousseaden, David ANDRE, Roberto Rodriguez @Cyb3rWard0g, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh124Free2022-08-06Windows Process Creation: Image contains NTFS 8.3 short filename patterns
Flags process creation events where the Image contains Windows 8.3 short-name patterns (e.g., ~1.exe, ~2.ps1) to evade image-based detections.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium376Free2022-08-06Azure Audit Logs: User Added to Privileged Eligibility Role
Alerts on Azure audit log events indicating a user was added as an eligible or permanent member to a privileged role.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh132Free2022-08-06Windows Exploit Guard Controlled Folder Access: Added Allowed Application for Blocked Path
Alerts when an app is added to Exploit Guard’s AllowedApplications list to bypass controlled folder restrictions for risky paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh113Free2022-08-05Windows Registry: Exploit Guard ProtectedFolders Value Deleted
Alerts on deletion of registry values under Exploit Guard Controlled Folder Access ProtectedFolders.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh121Free2022-08-05Windows Process Creation: wusa.exe Cab Extraction From Suspicious Directory Paths
Flags wusa.exe with /extract: originating from common temp/public paths, a potential CAB-based payload unpacking behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-08-05Windows Process Command Line Contains NTFS 8.3 Short Filename Patterns (~1/~2.*)
Detects Windows command lines referencing NTFS 8.3 short names like ~1.exe or ~2.ps1.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium151Free2022-08-05Windows Process Creation: Remove-MpPreference Used to Tamper Windows Defender Settings
Flags process executions that call Remove-MpPreference with Defender tampering-related parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-08-05Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh436Free2022-08-05Windows Suspicious File Creation in AppData Outside Common Subdirectories
Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh82Free2022-08-05Windows Defender Exploit Guard Tamper via Controlled Folder Access AllowedApplications or ProtectedFolders Changes
Alerts on Windefend EventID 5007 when Exploit Guard ProtectedFolders or AllowedApplications lists are modified.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh103Free2022-08-05Azure Audit Logs: Removal of Privileged Role Eligible Members
Flags Azure audit log events indicating bulk removal of eligible members from privileged roles.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh175Free2022-08-05Windows RDP Tunneling Using plink.exe on Local Port 3389
Alert on plink.exe command lines referencing 127.0.0.1:3389 or port 3389, suggesting potential RDP tunneling on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-08-04Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
Florian Roth (Nextron Systems), Microsoft (idea), Huntrule TeamWindowsprocess_creationHigh90Free2022-08-04Windows PsExec Named Pipe Creation from Suspicious Paths (PSEXESVC)
Alerts on PsExec pipe \PSEXESVC creation when the executing image path is in public/temp/desktop/downloads locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdMedium322Free2022-08-04