Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,321 rules
Windows Security: Suspicious Scheduled Task Update via Event ID 4702 Keywords
Alerts when a scheduled task is updated (EventID 4702) and the new task content includes suspicious execution keywords or temp/user paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh141Free2022-12-05Windows Security Audit: Scheduled Task Deleted or Disabled (Important Task Names)
Alerts on deletion or disabling of important Windows scheduled tasks based on Security audit events 4699 and 4701.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh445Free2022-12-05Windows Security: Suspicious Scheduled Task Creation via Event 4698
Alerts on Windows scheduled task creation (EventID 4698) when TaskContent contains suspicious directories or command patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh113Free2022-12-05Windows Process Execution of wsudo with System or TrustedInstaller
Alerts on wsudo.exe runs from wsudo-bridge.exe requesting execution as System or TrustedInstaller.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2022-12-02Windows DLL Sideloading via Loading ShellChromeAPI.dll
Alerts when Windows processes attempt to load ShellChromeAPI.dll, a DLL typically not present on systems.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh132Free2022-12-01Windows: Gpg4win (GnuPG) Encrypt/Decrypt Command Using Suspicious File Paths
Flags Gpg4win/GnuPG file crypto commands using -passphrase with activity in temporary/public or suspicious Windows directories.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-11-30Windows PowerTool Process Execution
Flags Windows process creation events where PowerTool.exe/PowerTool64.exe is launched.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3810Free2022-11-29Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.
Janantha Marasinghe, Huntrule TeamAzuresigninlogsHigh81Free2022-11-27Windows UAC Bypass via Event Viewer RecentViews Path in Process Command Line
Flags Windows processes whose command lines reference Event Viewer RecentViews and use redirection, consistent with UAC bypass techniques.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2022-11-22Windows Registry NGenAssemblyUsageLog Key Tampering via .NET Usage Log Configuration
Alerts on registry modifications to the .NETFramework NGenAssemblyUsageLog key that can disrupt .NET Usage Log creation.
frack113, Huntrule TeamWindowsregistry_setHigh176Free2022-11-18Windows file activity matching CrackMapExec/Impacket-secretsdump credential dumping temp output patterns
Alerts on Windows temp file creations consistent with CrackMapExec or Impacket-secretsdump credential dumping activity.
SecurityAura, Huntrule TeamWindowsfile_eventHigh3010Free2022-11-16Windows Driver Load: Process Hacker (processhacker.sys) Presence
Flags Windows driver loads of Process Hacker’s processhacker.sys using path and known imphash indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh143Free2022-11-16Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Alerts on Windows Code Integrity Event ID 3077 when an image/driver load is blocked for signing-level or policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh151Free2022-11-10Windows Process Creation: Sysmon.exe as Parent of Spawned Process
Alerts when Sysmon.exe/Sysmon64.exe is the parent of a new process, a potentially suspicious execution chain on Windows.
Florian Roth (Nextron Systems), Tim Shelton (fp werfault), Huntrule TeamWindowsprocess_creationHigh102Free2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-11-09