Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell Script: Remove Account From Domain Admin Group via Remove-ADGroupMember
Alerts on PowerShell commands removing specified members via Remove-ADGroupMember, potentially disrupting Domain Admin access.
frack113, Huntrule TeamWindowsps_scriptMedium121Free2021-12-26Windows Process Termination via taskkill.exe Execution
Alerts on taskkill.exe executions that use /f along with /im or /pid to force-terminate targeted processes.
frack113, MalGamy (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationLow70Free2021-12-26Windows: .txt Created on User Desktop via cmd.exe
Flags cmd.exe creating .txt files under user Desktop, a common ransomware-style artifact placement pattern.
frack113, Huntrule TeamWindowsfile_eventMedium100Free2021-12-26Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh70Free2021-12-22Windows: Detect Computer Account Rename to Non-Standard Name Missing Trailing '$'
Alerts on Windows 4781 computer account renames where the new name lacks the '$' suffix.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh82Free2021-12-22Proxy requests with URI ending in .class extension
Flags proxy requests whose URI path ends with .class, useful for identifying potential Java class downloads.
Andreas Hunkeler (@Karneades), Huntrule Team—proxyMedium60Free2021-12-21Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Alerts on Windows process executions using filenames that match common Sysinternals tools to indicate potential binary impersonation.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2021-12-20Suspicious Windows Process Creation as SYSTEM User with Likely Credential/Defense Evasion Commands
Flags SYSTEM-context process executions on Windows that include suspicious tool names or command-line patterns such as PowerShell/Mimikatz indicators.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindowsprocess_creationHigh122Free2021-12-20Windows Registry and PowerShell Modification of ms-settings Protocol Handler
Flags reg.exe or PowerShell registry edits that alter the ms-settings protocol handler open command path.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium288Free2021-12-20Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo
Alerts on sqlcmd.exe running a query targeting the VeeamBackup dbo Credentials table to dump sensitive credentials.
frack113, Huntrule TeamWindowsprocess_creationHigh343Free2021-12-20Windows: Detect sc.exe Service Creation with DACL Modification (sdset DCLCWPDTSD)
Alerts on sc.exe sdset usage with DCLCWPDTSD, suggesting permission changes to hide or impede service removal.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh60Free2021-12-20Windows reg.exe Credential Enumeration via Registry Query (HKLM/HKCU)
Flags reg.exe registry queries (REG_SZ, recursive) focused on HKLM/HKCU and PuTTY Sessions to enumerate credential material.
frack113, Huntrule TeamWindowsprocess_creationMedium2010Free2021-12-20PowerShell Credential Manager enumeration via vaultcmd /listcreds
Flags PowerShell using vaultcmd /listcreds to enumerate Windows/Web credential manager stored entries.
frack113, Huntrule TeamWindowsps_scriptMedium133Free2021-12-20PowerShell Credential Manager Credential Dump via Script Block Text Matching (Windows)
Alerts on PowerShell script blocks that invoke Windows Credential Manager credential retrieval functions.
frack113, Huntrule TeamWindowsps_scriptMedium4310Free2021-12-20PowerShell Credential Discovery via Recursive File Search and Select-String
Flags PowerShell script blocks that recursively list files and run select-string pattern searches, indicative of credential hunting.
frack113, Huntrule TeamWindowsps_scriptMedium144Free2021-12-19