Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,324 rules
Windows Task Scheduler: Detects Scheduled Task Deletion or Disabling (Task Deleted/Disabled)
Alert on deletion or disabling of targeted Windows scheduled tasks tied to system, security, and update components.
frack113, Huntrule TeamWindowstaskschedulerHigh244Free2023-01-13Windows Registry change enabling developer features for sideloading and untrusted app installs
Alerts on registry writes that enable Windows developer feature policies allowing sideloading of untrusted apps.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2023-01-12Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)
Flags Windows SRP enforcement events where attempts to access applications are restricted by administrator policy.
frack113, Huntrule TeamWindowsapplicationHigh467Free2023-01-12Windows process activity enabling Developer Mode or sideloading via SystemSettingsAdminFlows.exe
Alerts on SystemSettingsAdminFlows.exe command lines enabling Developer Mode unlock or application sideloading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-01-11Windows Process Creation: PowerShell Execution Policy Registry Tampering via CommandLine
Alerts when a process command line references PowerShell ExecutionPolicy registry paths and weaker policy values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2023-01-11Windows BITS Client Job Downloads from Direct IP Addresses
Alerts when Windows BITS Client downloads via HTTP/HTTPS URLs containing direct IP addresses.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsbits-clientHigh352Free2023-01-11Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh101Free2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh426Free2023-01-11Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh120Free2023-01-10Windows Suspicious Double-Extension Execution via Parent Command Line
Alerts on Windows processes launched by parents whose image/command line includes disguised double-extension tokens.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh169Free2023-01-06Windows PowerShell: ScriptBlock using security descriptor (Win32_Trustee/Win32_Ace) and LSA data strings
Alerts on PowerShell ScriptBlock text that manipulates security descriptors and LSA-related identifiers, indicating possible persistence behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh352Free2023-01-05Windows Registry AMSI COM Server Hijacking via InProcServer32 CLSID Modification
Alerts on registry changes that alter an AMSI COM CLSID InProcServer32 entry to break AMSI loading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh428Free2023-01-04Linux process execution matches known hacktools by image name
Alerts on Linux process executions of known hacktool, scanner, web enumeration, and exploit utility binaries by image name.
Nasreddine Bencherchali (Nextron Systems), Georg Lauenstein (sure[secure]), Huntrule TeamLinuxprocess_creationHigh403Free2023-01-03Windows Registry EventLog Service File Location Tampering
Flags registry modifications that change the EventLog service’s configured log file location on Windows.
D3F7A5105, Huntrule TeamWindowsregistry_setHigh161Free2023-01-02Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Alerts on Windows process launches whose command line includes well-known malicious PowerShell commandlet names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2023-01-02