Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Suspicious Scheduled Task Modification via schtasks /Change /TN
Flags schtasks.exe executions that modify existing scheduled tasks (/Change /TN) using suspicious locations and command-line payload tooling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh438Free2022-07-28Windows File Creation: Suspicious DLL/EXE/SYS in Spool Drivers Color Folder
Alerts on creation of .dll, .exe, or .sys files under C:\Windows\System32\spool\drivers\color.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium111Free2022-07-28Azure Audit Logs: Admin-initiated App Role Assignments and Privileged Delegated Permissions
Alerts on Azure audit events where an admin grants app roles to a service principal, enabling privileged application access.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh90Free2022-07-28Azure Audit Logs: End User Consent for Application (Non-Admin Consent)
Identifies end-user consent grants to applications in Azure AD audit logs.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsLow135Free2022-07-28Azure audit logs: Delegated highly privileged permissions granted for all users
Alerts on Azure audit log events where delegated permissions are granted to all users.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh90Free2022-07-28Windows Registry: Appx DebugPath Key for Potential Persistence
Detects registry set activity involving AppX DebugPath entries that may indicate persistence via packaged app debug configuration.
frack113, Huntrule TeamWindowsregistry_setMedium398Free2022-07-27Windows Browser Launched with Remote Debugging Flags
Alerts on Windows launches of Chromium-based browsers or Firefox with remote debugging command-line flags.
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium144Free2022-07-27Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Alerts on successful Azure AD sign-ins where MFA was not required and only single-factor authentication was used.
MikeDuddington, '@dudders1', Huntrule TeamAzuresigninlogsLow90Free2022-07-27Windows: WinRing0 Driver Load via Image Hash and File Name Match
Alerts on Windows driver loads matching WinRing0 modules by IMPhash or expected WinRing0 filenames.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh162Free2022-07-26Linux Process Creation: Base64-Encoded Pipe to Bash/Sh Execution
Flags Linux command lines that use base64-encoded data piped into bash or sh for execution.
pH-T (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium80Free2022-07-26Windows: Detect SelectMyParent PPID Spoofing Tool Execution
Flags SelectMyParent.exe process creation with PPID spoofing command-line and metadata indicators on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-07-23Suspicious PDQDeployRunner Execution on Windows with Encoded/Download Indicators
Alerts on child process activity from PDQDeployRunner parents showing encoded, hidden, or download-related command line indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-07-22Windows Service Installation: PDQDeployRunner Remote Service Creation (Service Control Manager)
Flags new Windows services installed with PDQDeployRunner-* naming via Service Control Manager event 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium153Free2022-07-22Windows: Detect New PDQDeploy Service Installation via Service Control Manager
Flags new Windows services installed via SCM Event 7045 that reference PDQDeployService.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium141Free2022-07-22Windows Registry SIP Persistence via New Cryptography Provider Registration
Detects suspicious Windows registry writes that register a new SIP/Cryptography provider DLL for persistence or defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium163Free2022-07-21