Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Command Line Containing Whoami as First Parameter
Flags Windows process creations with command lines containing '.exe whoami' to surface potential discovery behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2021-11-29Windows Regsvr32.exe Executed with Suspicious File Extension Masquerading as DLL
Alerts when REGSVR32.exe runs with a command-line argument ending in a suspicious masquerade file extension.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh151Free2021-11-29Windows File Writes from NPPSpy Hacktool: NPPSpy.txt and NPPSpy.dll
Alerts on Windows file events writing NPPSpy.txt or NPPSpy.dll, consistent with credential dumping by the NPPSpy hacktool.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh102Free2021-11-29Linux auditd: getcap scanning for setuid/setgid-capable files under root
Flags getcap command-line usage scanning / for Linux capability-bearing files via auditd.
Pawel Mazur, Huntrule TeamLinuxauditdLow153Free2021-11-28Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
Florian Roth (Nextron Systems), Samir Bousseaden, Huntrule TeamWindowsprocess_creationCritical382Free2021-11-27Windows Process Access to LSASS Memory From Suspicious Source Paths
Alerts on processes attempting sensitive access to lsass.exe originating from suspicious/temp directories, using granted access and source path context.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessMedium70Free2021-11-27Windows extrac32.exe CAB extraction via Alternate Data Stream execution
Flags Windows executions of extrac32.exe that target a .cab and include an alternate data stream path indicator.
frack113, Huntrule TeamWindowsprocess_creationMedium143Free2021-11-26Windows Diantz.exe Command-Line ADS CAB Creation
Flags Diantz commands that create or reference a .cab using an Alternate Data Stream (ADS) pattern on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium286Free2021-11-26Windows Process Creation: Dump64.EXE Renamed into Visual Studio Folder
Alerts on Visual Studio–staged dump64.exe masquerading, potentially indicating an attempt to bypass Windows Defender AV.
Austin Songer @austinsonger, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2021-11-26Windows ConfigSecurityPolicy.EXE Used for HTTP/FTP Arbitrary File Transfers
Alert when ConfigSecurityPolicy.exe runs with ftp/http/https URLs in the command line, indicating potential file transfer abuse.
frack113, Huntrule TeamWindowsprocess_creationMedium133Free2021-11-26Azure Sign-in Auth Interruption: DeviceAuthenticationRequired/Failed and External Security Challenge
Alerts on Azure sign-in authentication interruptions tied to device authentication and external security challenge failures.
Austin Songer @austinsonger, Huntrule TeamAzuresigninlogsMedium162Free2021-11-26Azure AuditLogs: Privileged role assignment to user access admin
Flags Azure AuditLogs events where a user is assigned to User Access Administrator, enabling full subscription management.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsHigh163Free2021-11-26Azure Activity Logs: Authorization ElevateAccess Grants Subscription-Level Management
Alerts on Azure Activity Log authorization elevation actions that can grant access to manage all subscriptions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsHigh122Free2021-11-26Windows Process Execution of Extexport.exe Suggesting Potential DLL Sideloading
Flags execution of Extexport.exe on Windows, which can be abused to side-load DLLs via crafted command lines.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2021-11-26Windows PowerShell Clears Console History via Clear-History
Flags PowerShell attempts to clear or delete console/PSReadline command history to hinder command forensics.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptHigh60Free2021-11-25