Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows rundll32 Execution With Uncommon DLL/CPL/INF Extension in Command Line
Alerts on Windows rundll32 executions whose command lines lack common .cpl/.dll/.inf endings, indicating potential unusual invocation.
Tim Shelton, Florian Roth (Nextron Systems), Yassine Oukessou, Huntrule TeamWindowsprocess_creationMedium4110Free2022-01-13Windows Sysmon Configuration Change (Event ID 16)
Alerts on Sysmon configuration changes via Sysmon Event ID 16 on Windows.
frack113, Huntrule TeamWindowssysmonMedium113Free2022-01-12Windows: Process creation event for Sysmon uninstall using Sysmon -u
Flags attempts to uninstall Sysmon on Windows by running Sysmon with the -u flag.
frack113, Huntrule TeamWindowsprocess_creationHigh419Free2022-01-12PowerShell Script Creates Volume Shadow Copy via Win32_ShadowCopy
Alerts when PowerShell script blocks invoke Win32_ShadowCopy.Create to create a ClientAccessible shadow copy.
frack113, Huntrule TeamWindowsps_scriptHigh161Free2022-01-12Windows ProcDump renamed, copied or moved for stealth evasion
Alerts on ProcDump commands that copy/move or rename dump outputs, including LSASS dump filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2022-01-11Windows regsvr32 Downloads Remote DLLs via HTTP/HTTPS IP in /i Parameter
Alerts when regsvr32 is invoked with an /i: HTTP/HTTPS IP pattern to fetch remote DLLs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2022-01-11Windows Process Execution: Microsoft.NodejsTools.PressAnyKey.exe Child Spawns
Flags child processes started by Microsoft.NodejsTools.PressAnyKey.exe, which may be abused to run arbitrary binaries.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-01-11Windows mpiexec.exe LOLBin: Flag combination with -n/n 1 for potential arbitrary execution
Alerts on Windows executions of mpiexec.exe with /n 1 or -n 1, correlated to a specific imphash, indicating LOLBin-style behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2022-01-11Windows: Detect devinit.exe MSI download flag combo (-t msi-install, -i http)
Alerts on devinit.exe command lines that combine MSI install with an HTTP download source.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2022-01-11Windows Browser Process Spawned with Inline URL Pointing to Suspicious File Extension
Flags Windows browser processes launched with an inline HTTP URL pointing to files with suspicious extensions.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium364Free2022-01-11Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Alerts on creation of ntds.dit on Windows when the creator process image/path is uncommon or located in suspicious directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh131Free2022-01-11Windows WScript/CScript File Write With Script Extensions to Temp or Startup Paths
Alerts when WScript/CScript writes script files (.js/.vbs/.wsf/.wsh, etc.) into common temp or Startup directories.
Tim Shelton, Huntrule TeamWindowsfile_eventHigh459Free2022-01-10Windows ChromeLoader Execution via Scheduled Task and Hidden PowerShell Launch
Flags PowerShell-launched chrome.exe that uses --load-extension from local AppData Chrome paths for ChromeLoader-style execution.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh92Free2022-01-10Windows Registry: Disable Microsoft Defender Firewall by Setting EnableFirewall to 0
Flags Windows Registry changes that disable Defender firewall by setting EnableFirewall DWORD to 0.
frack113, Huntrule TeamWindowsregistry_setMedium153Free2022-01-09Windows netsh Enables Defender Firewall Group Rules via advfirewall set rule group new enable=Yes
Flags netsh.exe command lines that create and enable Microsoft Defender Firewall group rules (enable=Yes).
frack113, Huntrule TeamWindowsprocess_creationMedium209Free2022-01-09