Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,320 rules
PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
Tim Rauch, frack113, Huntrule TeamWindowsps_scriptHigh204Free2022-09-20Windows: Detects NetSupport RAT client32.exe execution using Imphash and filename metadata
Flags renamed NetSupport RAT client32.exe launches on Windows using a specific Imphash and file metadata, while filtering a matching image path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-09-19Windows: Detect winPEAS privilege escalation reconnaissance execution
Flags Windows executions of winPEAS/PEASS-ng based on image name and command-line discovery options and release download indicators.
Georg Lauenstein (sure[secure]), Huntrule TeamWindowsprocess_creationHigh408Free2022-09-19Windows Registry: Tampering ChannelAccess Permissions for WINEVT Event Channels
Alerts on registry updates to WINEVT ChannelAccess that set SDDL permissions granting elevated access to event channels.
frack113, Huntrule TeamWindowsregistry_setHigh322Free2022-09-17Windows Security 4663: Access to Microsoft Teams token and local storage files
Identifies non-Teams.exe processes accessing Microsoft Teams cookies or local storage objects on Windows (Event 4663).
"@SerkinValery, Huntrule Team"WindowssecurityHigh121Free2022-09-16Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Detects SharPersist execution on Windows via process name and persistence-related command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh156Free2022-09-15Windows: Service Created by System Using Client with PID 0 (SCM Event 7045)
Alerts on Windows service installation events (SCM EventID 7045) where the client process ID is 0.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowssystemHigh391Free2022-09-15Windows Service Created by Client With PID 0 or Parent PID 0
Alerts on Windows service installs (EID 4697) where the client or parent PID is 0.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh162Free2022-09-15Windows UAC Bypass via Elevated COM interface using ICMLuaUtil
Flags dllhost.exe parent launches tied to elevated COM /Processid GUIDs consistent with UAC bypass behavior on Windows.
Florian Roth (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-13Windows: Taskkill used to terminate ccSvcHst.exe (Symantec Endpoint Protection service impairment)
Flags Windows taskkill /F /IM ccSvcHst.exe executions that can disable Symantec Endpoint Protection services.
Ilya Krestinichev, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh381Free2022-09-13Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution
Flags Windows executions of chisel.exe with client/server tunneling and SOCKS5 reverse arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-09-13Windows Process Creation: 3proxy Proxy Server Execution
Detects execution of 3proxy.exe with local 127.0.0.1 proxy binding on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2022-09-13PowerShell Disable-WindowsOptionalFeature -Online -FeatureName for Windows Defender features
Detects PowerShell disabling online Windows Defender features via Disable-WindowsOptionalFeature -FeatureName.
frack113, Huntrule TeamWindowsps_scriptHigh411Free2022-09-10Windows Schtasks.exe Scheduled Task Creation or Modification with Suspicious Schedule Types
Alerts on schtasks.exe commands that schedule tasks using ONLOGON/ONSTART/ONCE/ONIDLE with potentially malicious privilege context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh204Free2022-09-09Windows schtasks Delete All Scheduled Tasks via /tn * /delete /f
Flags schtasks.exe commands that forcibly delete all scheduled tasks on the local host using /delete /tn * /f.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-09