Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
PowerShell Hyper-V Cmdlets Execution via Script Blocks (New-VM, Set-VMFirmware, Start-VM)
Alerts when PowerShell script blocks use Hyper-V VM creation or start cmdlets (New-VM, Set-VMFirmware, Start-VM).
frack113, Huntrule TeamWindowsps_scriptMedium122Free2022-04-09Windows File Access to Browser Credential Stores by Uncommon Processes
Detects suspicious process access to Firefox/Chromium credential store files on Windows, excluding common system and known benign paths.
frack113, X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessLow60Free2022-04-09Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Flags VaultCmd.exe executions that enumerate saved Windows Credential Manager entries using /listcreds.
frack113, Huntrule TeamWindowsprocess_creationMedium141Free2022-04-08Windows Process Creation: SQLite Access to Firefox Profile Databases
Alerts when Windows runs SQLite tooling to query Firefox profile DBs like cookies.sqlite or places.sqlite.
frack113, Huntrule TeamWindowsprocess_creationHigh92Free2022-04-08Windows Task Scheduler persistence using svchost-launched PowerShell with hidden/Bypass flags
Alerts on svchost.exe Schedule tasks spawning PowerShell with hidden window and execution policy bypass flags.
pH-T (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-04-08Windows PowerShell execution from C:\Users\Public
Flags PowerShell command lines that reference C:\Users\Public, indicating likely script execution from a common public staging area.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2022-04-06Windows Process Creation: Node.js Executions from Adobe Creative Cloud
Flags Windows executions of Adobe Creative Cloud’s bundled node.exe, excluding typical JS resource paths.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium438Free2022-04-06Windows: Detect Suspicious DumpMinitool.exe Execution via Process Command-Line
Alerts on suspicious command-line usage of DumpMinitool.exe on Windows, leveraging process creation Image, OriginalFileName, and command-line text.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-04-06Windows: Detect DumpMinitool.exe Execution for Process Memory Dumping
Identifies Windows executions of DumpMinitool.exe variants with dump options via process creation telemetry.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-04-06Windows Security: Outgoing Logon (LogonType 9) Using New Credentials (4624)
Flags Windows 4624 LogonType 9 events where new credentials are used for authentication.
Max Altgelt (Nextron Systems), Huntrule TeamWindowssecurityLow111Free2022-04-06Windows Registry: New Root CA or AuthRoot Certificates Added to Certificate Stores
Alerts on registry certificate-store writes adding new Root/CA/AuthRoot certificates as binary blobs.
frack113, Huntrule TeamWindowsregistry_setMedium312Free2022-04-04Windows Registry Key Change Disabling System Restore
Detects registry writes that disable Windows System Restore via policy/config keys set to DWORD 0x00000001.
frack113, Huntrule TeamWindowsregistry_setHigh211Free2022-04-04Windows Registry Service Persistence via SafeBoot Control Keys
Flags Windows registry writes that configure a service to load in Safe Mode (SafeBoot Minimal/Network).
frack113, Huntrule TeamWindowsregistry_setHigh92Free2022-04-04Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
frack113, Huntrule TeamWindowsps_scriptLow153Free2022-04-04Windows Registry Key Changes Disabling PowerShell Logging for Current User
Detects registry changes that disable PowerShell module/script logging and transcription by setting logging keys to DWORD 0.
frack113, Huntrule TeamWindowsregistry_setHigh448Free2022-04-02