Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry Change Disabling Hidden and System File Display
Detects registry writes that disable Windows Explorer showing hidden/system files by setting Hidden and ShowSuperHidden to 0x0.
frack113, Huntrule TeamWindowsregistry_setMedium146Free2022-04-02Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage
Flags PowerShell script blocks that use GetTypeFromCLSID followed by ShellExecute.
frack113, Huntrule TeamWindowsps_scriptMedium133Free2022-04-02Windows fsutil.exe Drive Enumeration via Process Execution
Flags fsutil.exe process launches with command lines referencing connected drive enumeration.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow102Free2022-03-29Windows PowerShell IEX Invocation Patterns in Process Creation Command Lines
Alerts on suspicious PowerShell command lines that pipe or otherwise invoke IEX and may include Base64 decoding.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-03-24Windows PowerShell Download and Execution Cradles
Flags PowerShell commands that download remote content and immediately execute it using IEX/Invoke-Expression.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh272Free2022-03-24Azure Sign-in Logs: MFA Denied Based on Authentication Requirement
Flags Azure sign-ins requiring MFA where the status indicates "MFA Denied."
AlertIQ, Huntrule TeamAzuresigninlogsMedium113Free2022-03-24Windows: reg.exe Registry Tampering of Windows Defender Policy Keys
Detects reg.exe adding Defender DWORD policy values to disable or suppress multiple protection features via Windows registry.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2022-03-22Windows LSA PPL Protection Setting Modification via reg.exe or PowerShell Command Line
Flags Windows command lines that alter LSA PPL-related Control\Lsa registry settings using reg.exe/PowerShell property changes.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium132Free2022-03-22Windows Suspicious Parent Processes: Unusual Child Creation by System Utilities
Alerts when predefined suspicious Windows parent executables spawn unusual or unrecognized child processes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2022-03-21Windows Service Control Manager: HackTool Service Installation or Start via Suspicious Service Names
Detects Windows service creation/start events tied to hacktool-like service names or ImagePath indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh362Free2022-03-21Windows Scheduled Task Backdoor Execution via cmd.exe or PowerShell (System EventID /create /delete)
Flags cmd.exe/powershell.exe command lines that create a System/EventID-based scheduled task to run a payload.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh233Free2022-03-21Windows Registry Policy Modification for Explorer UI Function Disabling
Flags Windows Explorer policy registry value writes (DWORD 0x1) that disable Explorer functions or UI elements.
frack113, Huntrule TeamWindowsregistry_setMedium418Free2022-03-18Windows Registry Defense Impairment via Explorer Hide* Policy Values
Flags registry set events that change Explorer hide-related DWORD values under Windows policy keys to impair user visibility.
frack113, Huntrule TeamWindowsregistry_setMedium3710Free2022-03-18Windows Registry Policy Change to Disable/Impair Internal Tools and UI Features
Detects registry policy edits that disable Windows tools/features or alter related system behavior via specific DWORD values.
frack113, Nasreddine Bencherchali (Nextron Systems), CrimpSec, Huntrule TeamWindowsregistry_setMedium162Free2022-03-18Windows Service Installation via Scripted ImagePath Indicators (Event 7045)
Identifies suspicious Windows service installations that embed script host execution via Event ID 7045 ImagePath patterns.
pH-T (Nextron Systems), Huntrule TeamWindowssystemHigh446Free2022-03-18