Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Microsoft Sync Center (mobsync.exe) Network Connections to Public IPs
Alerts when mobsync.exe makes outbound connections to destination IPs outside private/local ranges.
elhoim, Huntrule TeamWindowsnetwork_connectionMedium327Free2022-04-28Windows: Copying Executable or DLL Files into Default GPO Policies Folder
Alerts when .exe/.dll files are created in the default GPO storage folder path.
elhoim, Huntrule TeamWindowsfile_eventMedium4010Free2022-04-28Windows: Files created by Microsoft Sync Center (mobsync.exe) with .dll/.exe extensions
Flags .dll and .exe files created by mobsync.exe on Windows.
elhoim, Huntrule TeamWindowsfile_eventMedium264Free2022-04-28Windows: rundll32.exe spawning explorer.exe child process (shell32.Control_RunDLL)
Alerts on rundll32.exe spawning explorer.exe, an uncommon child process pattern that may indicate stealthy execution via shell components.
elhoim, CD_ROM_, Huntrule TeamWindowsprocess_creationHigh142Free2022-04-27Windows Process Creation: KrbRelay.exe Kerberos Relay Tool Execution
Flags Windows process creation for KrbRelay.exe with Kerberos relaying-related command-line arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-04-27Windows Hacktool Execution via PE Metadata Company Field
Flags execution of Windows binaries with PE Company metadata set to "Cube0x0", even when renamed.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-04-27Windows UAC Bypass via Event Viewer RecentViews File Creation
Alerts on suspicious file events to Event Viewer RecentViews paths that may indicate a Windows UAC bypass attempt.
Antonio Cocomazzi (idea), Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh269Free2022-04-27Windows: Detect .SCR screen saver file creation outside common system directories
Alerts on creation of .scr screen saver files in unusual locations on Windows.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamWindowsfile_eventMedium277Free2022-04-27Windows Successful Local Kerberos Logon to Built-in Administrator (Possible Privilege Escalation)
Alert on successful local (127.0.0.1) Kerberos logons targeting the built-in Administrator SID for potential privilege escalation.
Elastic, @SBousseaden, Huntrule TeamWindowssecurityHigh102Free2022-04-27Windows: Detect KrbRelayUp.exe HackTool Process Execution
Flags Windows process executions of KrbRelayUp.exe with relay/domain and SCM spawn command-line patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh359Free2022-04-26Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server
Flags LsaSrv events 6038/6039 showing NTLMv1 authentication between client and server on Windows.
Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium275Free2022-04-26Windows Sysmon Application Popup Crash (Event ID 26)
Flags Application Popup events reporting sysmon64.exe/sysmon.exe “Application Error” (Event ID 26).
Tim Shelton, Huntrule TeamWindowssystemHigh104Free2022-04-26Suspicious Child Process Spawning by PowerShell on Windows
Alerts when PowerShell spawns potentially suspicious child binaries (e.g., certutil, mshta, wmic, rundll32), with exclusions for known benign patterns.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationMedium80Free2022-04-26Windows Process Creation: Suspicious PowerShell Child of Tomcat prunsrv.exe (CVE-2022-22954 Attempt)
Alerts when prunsrv.exe spawns PowerShell or cmd.exe running PowerShell, consistent with potential Workspace ONE Access RCE attempts.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium161Free2022-04-25Windows msiexec.exe Command Line Loading a DLL and Calling DllUnregisterServer
Alert when msiexec.exe runs with -z and a .dll on the command line, consistent with DLL DllUnregisterServer execution.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2022-04-24