Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Scheduled Task Creation via schtasks with Suspicious Command-Line Patterns
Flags schtasks.exe /Create commands containing suspicious interpreter, encoding, hidden execution, or unusual path/script components.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh432Free2022-02-23Windows explorer.exe spawned with /NOUACCHECK flag for UAC bypass behavior
Alerts on explorer.exe executions that include /NOUACCHECK, indicating potential bypass of UAC checks for child processes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-02-23Windows scheduled task creation via schtasks.exe from suspicious parent path
Flags schtasks.exe /Create when spawned from temp or user-writable parent directories on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-02-23Windows Schtasks.exe Task Creation Targeting Suspicious Paths or Env Variables
Alerts when schtasks.exe creates tasks whose target path/arguments reference suspicious folders or common environment variables.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium161Free2022-02-21Windows CHCP Console Code Page Lookup Triggered From cmd.exe
Flags cmd.exe-launched chcp.com executions likely used to query system code page/locale for discovery.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationMedium192Free2022-02-21Suspicious Reset-ComputerMachinePassword Usage via PowerShell on Windows
Detects PowerShell executions of Reset-ComputerMachinePassword that may indicate attempts to alter domain computer account authentication.
frack113, Huntrule TeamWindowsps_moduleMedium134Free2022-02-21Windows Process Execution of Tor or Tor Browser (tor.exe / Firefox-based)
Flags Windows execution of tor.exe or Tor Browser’s bundled Firefox from the expected installation path.
frack113, Huntrule TeamWindowsprocess_creationHigh112Free2022-02-20Windows Sysmon DNS Query to .onion or Tor Gateway Domains
Alerts when Windows Sysmon DNS queries target .onion or Tor gateway/proxy-related domain suffixes.
frack113, Huntrule TeamWindowsdns_queryHigh377Free2022-02-20Windows DNS Client Query for .onion and Tor-related Domains
Alerts on Windows DNS queries resolving .onion and related Tor/hidden-service domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientHigh93Free2022-02-20Windows Firewall Settings Change Events (Windows Firewall/Defender Firewall-AS)
Alert on Windows Firewall/Defender firewall setting changes using Events 2002, 2003, 2008, 2082, and 2083.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asLow142Free2022-02-19Windows Defender Firewall Reset to Default Configuration (Firewall-as Service)
Flags Windows where Windows Defender Firewall is reset to default settings via firewall-as events.
frack113, Huntrule TeamWindowsfirewall-asLow71Free2022-02-19Windows Defender Firewall Service Failed to Load Group Policy (Event ID 2009)
Alert on Event ID 2009 when the Windows Defender Firewall service cannot load Group Policy.
frack113, Huntrule TeamWindowsfirewall-asLow4210Free2022-02-19Windows Firewall exception rule deleted (Windows Firewall/Defender) EventID 2006/2052
Flags deletion of Windows Defender Firewall exception rules using EventID 2006 or 2052 with modifying application context.
frack113, Huntrule TeamWindowsfirewall-asMedium335Free2022-02-19Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)
Alerts on Windows Firewall exception rule additions (Event IDs 2004/2071/2097), excluding common benign paths.
frack113, Huntrule TeamWindowsfirewall-asMedium432Free2022-02-19Windows Firewall Exception List Rule Modified (Firewall-as Events 2005/2073)
Flags Windows Defender Firewall exception list changes (Event IDs 2005/2073), indicating potential attacker-driven network access changes.
frack113, Huntrule TeamWindowsfirewall-asLow80Free2022-02-19