Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Delete Backup or System State Backups via wbadmin.exe
Flags wbadmin.exe command lines that delete backup or system state backups, potentially impacting recovery.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium141Free2021-12-13Windows wbadmin.exe Deletes All Backup Copies (keepVersions:0)
Flags wbadmin.exe executions that delete all backups/system state backups using keepVersions:0.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-12-13Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
frack113, Huntrule TeamWindowsprocess_creationHigh245Free2021-12-13Windows CMD dir /S File and Subfolder Enumeration
Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.
frack113, Huntrule TeamWindowsprocess_creationLow91Free2021-12-13PowerShell Script Block Collection of Browser Bookmarks via Get-ChildItem
Detects PowerShell Get-ChildItem activity used to recursively enumerate browser bookmarks from a target path.
frack113, Huntrule TeamWindowsps_scriptLow152Free2021-12-13Windows Process Discovery via wmic.exe "group" Flag
Flags wmic.exe process executions querying local group information via a "group" command-line argument.
frack113, Huntrule TeamWindowsprocess_creationLow298Free2021-12-12PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
frack113, Huntrule TeamWindowsps_scriptLow319Free2021-12-12PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
frack113, Huntrule TeamWindowsps_moduleLow111Free2021-12-12Webserver JNDI-Exploit-Kit Exploitation Indicators via Known Payload Paths
Flags webserver requests whose URL paths match known JNDI-Exploit-Kit exploit, deserialization, and memshell pattern strings.
Florian Roth (Nextron Systems), Huntrule TeamWebwebserverHigh162Free2021-12-12Windows Process Discovery via tasklist Command Execution
Alerts on Windows executions of tasklist.exe used for running process discovery.
frack113, Huntrule TeamWindowsprocess_creationInformational120Free2021-12-11Windows Process Creation: Nmap/Zenmap (nmap.exe or zennmap.exe) Execution
Flags Windows execution of Nmap/Zenmap (nmap.exe or zennmap.exe) used for remote service discovery.
frack113, Huntrule TeamWindowsprocess_creationMedium151Free2021-12-10Windows Net.exe Network Connections Discovery via Use Sessions Query
Flags net.exe/net1.exe commands using 'use sessions' to enumerate network connection/session information.
frack113, Huntrule TeamWindowsprocess_creationLow120Free2021-12-10Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Alerts when SharpView.exe runs with command-line indicators of AD and network discovery/enumeration activity.
frack113, Huntrule TeamWindowsprocess_creationHigh162Free2021-12-10PowerShell Get-NetTCPConnection Network Connection Discovery (Windows)
Detects PowerShell use of Get-NetTCPConnection to enumerate TCP network connections for discovery.
frack113, Huntrule TeamWindowsps_moduleLow101Free2021-12-10Windows PowerShell: Query TCP connections with Get-NetTCPConnection
Detects PowerShell usage of Get-NetTCPConnection to enumerate TCP network connections.
frack113, Huntrule TeamWindowsps_classic_startLow402Free2021-12-10