Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Creation: Suspicious Kernel Dump via dtrace.exe lkd(0) and syscall:::return
Alerts on Windows process executions of dtrace.exe with command lines consistent with kernel dumping (lkd).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh336Free2021-12-28PowerShell ScriptBlock Requests Kerberos Tickets via IdentityModel Token Assembly
Alerts on PowerShell ScriptBlock text that builds Kerberos ticket requests using KerberosRequestorSecurityToken and .GetRequest().
frack113, Huntrule TeamWindowsps_scriptHigh132Free2021-12-28PowerShell Script Blocks Register Malicious XLL via Office COM Automation on Windows
Detects PowerShell Script Block content that uses COM automation to call .RegisterXLL for an Office XLL add-in.
frack113, Huntrule TeamWindowsps_scriptHigh414Free2021-12-28Windows PowerShell Local User Account Manipulation via Script Block Logging
Alerts when PowerShell script blocks invoke local user management cmdlets that can be used to maintain persistence.
frack113, Huntrule TeamWindowsps_scriptMedium299Free2021-12-28PowerShell AD Account Creation Library Usage via AccountManagement Namespace on Windows
Alert on PowerShell Script Block content referencing System.DirectoryServices.AccountManagement, indicating potential AD principal manipulation.
frack113, Huntrule TeamWindowsps_scriptMedium311Free2021-12-28PowerShell Scheduled Task Creation via ScriptBlock Logging
Identifies PowerShell script blocks that create and register scheduled tasks using TaskScheduler cmdlets or CIM WMI method calls.
frack113, Huntrule TeamWindowsps_scriptMedium92Free2021-12-28Windows PowerShell Screen Capture via CopyFromScreen
Flags PowerShell scripts containing .CopyFromScreen, indicative of desktop screen capture activity.
frack113, Huntrule TeamWindowsps_scriptMedium101Free2021-12-28Windows Suspicious File Downloads from Outlook/OneNote Attachment Domains via Command-Line
Flags Windows command-line downloads using curl/wget or PowerShell from Outlook/OneNote attachment domains.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2021-12-27Windows Process Execution of Hashcat.exe for Password Cracking
Alerts on Hashcat.exe launched with cracking-focused flags targeting an offline SAM-derived dataset.
frack113, Huntrule TeamWindowsprocess_creationHigh409Free2021-12-27Windows: Findstr searches GPP cpassword in SYSVOL XML
Alerts when Windows findstr/find searches SYSVOL XML files for GPP cpassword.
frack113, Huntrule TeamWindowsprocess_creationHigh417Free2021-12-27Windows PowerShell Credential Guessing via LDAP using System.Net.NetworkCredential
Detects PowerShell scripts referencing LDAP connection and .NET network credential handling, potentially indicating remote credential access activity.
frack113, Huntrule TeamWindowsps_scriptLow141Free2021-12-27Windows PowerShell Copies a DLL into System32 or SysWOW64
Flags PowerShell Copy-Item targeting Windows\System32 or Windows\SysWOW64 for file placement.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2021-12-27Windows schtasks.exe /disable Used to Disable Security-Critical Scheduled Tasks
Flags schtasks.exe executions using /disable against security-critical Windows scheduled task paths.
frack113, Nasreddine Bencherchali (Nextron Systems), X__Junior, Huntrule TeamWindowsprocess_creationHigh71Free2021-12-26Windows: cipher.exe Overwrites Deleted Data Using /w
Flags Windows cipher.exe runs with /w: to overwrite deleted data on disk.
frack113, Huntrule TeamWindowsprocess_creationMedium345Free2021-12-26Windows PowerShell Wallpaper Replacement via Registry and SystemParametersInfo
Identifies PowerShell script blocks that modify the HKCU Desktop\WallPaper setting to replace a user’s wallpaper.
frack113, Huntrule TeamWindowsps_scriptLow302Free2021-12-26