Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,314 rules
Windows Registry: Exploit Guard ProtectedFolders Value Deleted
Alerts on deletion of registry values under Exploit Guard Controlled Folder Access ProtectedFolders.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh121Free2022-08-05Windows Process Creation: wusa.exe Cab Extraction From Suspicious Directory Paths
Flags wusa.exe with /extract: originating from common temp/public paths, a potential CAB-based payload unpacking behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-08-05Windows Process Creation: Remove-MpPreference Used to Tamper Windows Defender Settings
Flags process executions that call Remove-MpPreference with Defender tampering-related parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-08-05Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh436Free2022-08-05Windows Suspicious File Creation in AppData Outside Common Subdirectories
Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh82Free2022-08-05Windows Defender Exploit Guard Tamper via Controlled Folder Access AllowedApplications or ProtectedFolders Changes
Alerts on Windefend EventID 5007 when Exploit Guard ProtectedFolders or AllowedApplications lists are modified.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh103Free2022-08-05Azure Audit Logs: Removal of Privileged Role Eligible Members
Flags Azure audit log events indicating bulk removal of eligible members from privileged roles.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh175Free2022-08-05Windows RDP Tunneling Using plink.exe on Local Port 3389
Alert on plink.exe command lines referencing 127.0.0.1:3389 or port 3389, suggesting potential RDP tunneling on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-08-04Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
Florian Roth (Nextron Systems), Microsoft (idea), Huntrule TeamWindowsprocess_creationHigh90Free2022-08-04Windows Security Mitigations: Unsigned DLL Blocked from User-Writable Paths
Alerts on blocked unsigned DLL loads targeting public, downloads, desktop, or temp directories in Windows Security Mitigations logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurity-mitigationsHigh132Free2022-08-03Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2310Free2022-08-02Windows PowerShell Invoke-WebRequest Download to Suspicious Paths
Alert when PowerShell uses Invoke-WebRequest/aliases with download flags and targets suspicious file locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-08-02Windows: Detect VMwareXferlogs.exe Executed from Non-default Path
Alert on VMwareXferlogs.exe launching from an unexpected directory, a potential DLL sideloading technique on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh125Free2022-08-02Windows mpclient.dll Sideloading via MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when mpclient.dll is loaded by MpCmdRun.exe or NisSrv.exe outside known Windows Defender directories.
Bhabesh Raj, Huntrule TeamWindowsimage_loadHigh82Free2022-08-02Windows: Potential DLL sideloading via VMwareXferlogs loading glib-2.0.dll from non-standard path
Alerts on VMwareXferlogs.exe loading glib-2.0.dll from outside the default VMware directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh2810Free2022-08-02