Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Process Execution of PsLogList with Event Log Dump/Export Flags
Detects PsLogList executions aimed at Security/Application/System logs with dump/export/clear command-line switches.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium163Free2021-12-18Windows CleanWipe-Like PUA Execution via System Tool Uninstall Switches
Flags Windows processes launching CleanWipe-like removal tools with uninstall parameters for security impairment investigation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh229Free2021-12-18Windows Process Creation: Advanced Port Scanner PUA Execution via /portable /lng
Flags Windows launches of Advanced Port Scanner with /portable and /lng parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2021-12-18Windows Process Command-Line Flags Indicating Auditpol Policy Tampering
Detects auditpol runs with flags that disable key audit categories, indicating potential audit policy tampering for defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-12-18Windows: java.exe Parent Spawning cmd/powershell/bash Processes
Alerts when java.exe launches cmd, PowerShell, or bash on Windows, a potential sign of command execution.
Andreas Hunkeler (@Karneades), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium70Free2021-12-17Windows: Alert on Java.exe Spawning Suspicious System and Script Binaries
Triggers when java.exe launches a child utility commonly abused for command execution and administration.
Andreas Hunkeler (@Karneades), Florian Roth, Huntrule TeamWindowsprocess_creationHigh70Free2021-12-17Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
frack113, Huntrule TeamWindowsprocess_creationHigh403Free2021-12-16PowerShell Security Software Discovery Using get-process Piped to where-object (Windows)
Flags PowerShell scripts that enumerate processes and filter results for security software by vendor/product keywords.
frack113, Anish Bogati, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium161Free2021-12-16Windows PowerShell: Query SMB Shares via Get-SmbShare
Alerts on PowerShell script blocks running Get-SmbShare to discover SMB shares.
frack113, Huntrule TeamWindowsps_scriptLow103Free2021-12-15PowerShell ScriptBlock Enumeration of AD Group Membership and User Attributes (Windows)
Flags PowerShell script blocks querying AD group membership and user details for discovery of privileged directory information.
frack113, Huntrule TeamWindowsps_scriptLow351Free2021-12-15PowerShell Module: Get-SmbShare Used for SMB Share Discovery
Detects PowerShell module usage of Get-SmbShare to enumerate SMB shares across networked systems.
frack113, Huntrule TeamWindowsps_moduleLow465Free2021-12-15PowerShell module enumeration of AD principals via get-ADPrincipalGroupMembership
Flags PowerShell module usage of Get-ADPrincipalGroupMembership and Get-ADUser with -pr -f patterns indicative of AD discovery.
frack113, Huntrule TeamWindowsps_moduleLow234Free2021-12-15Windows Directory Services: CVE-2021-42287 SAMAccountName spoofing validation failures
Looks for Directory Services SAM validation failures (Event 16990/16991) that may indicate CVE-2021-42287 exploitation attempts.
frack113, Huntrule TeamWindowssystemMedium2810Free2021-12-15Windows Kerberos Key Distribution Center: CVE-2021-42278 Exploitation Attempt Indicators (Event 35–38)
Alerts on Windows Kerberos KDC ticket anomalies (EventIDs 35–38) associated with CVE-2021-42278 exploitation attempts.
frack113, Huntrule TeamWindowssystemMedium412Free2021-12-15Windows process execution of where.exe with browser bookmark database or history artifacts
Alerts on where.exe executions referencing browser history/bookmarks/cookie database artifacts in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow102Free2021-12-13