Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows UAC Bypass via IEInstal.exe Launching consent.exe from Temp with Elevated Integrity
Alerts on elevated consent.exe spawned by ieinstal.exe from Temp, indicating a possible Windows UAC bypass chain.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2021-08-30Windows UAC Bypass via DismHost.exe DLL Hijacking
Flags DismHost.exe executions from AppData\Local\Temp running as High/System integrity, consistent with UAC bypass via DLL hijacking.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-30Windows UAC Bypass via Disk Cleanup cleanmgr.exe run from Scheduled Task
Flags scheduled-task executions of cleanmgr.exe with disk-cleanup parameters running at high/System integrity.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh159Free2021-08-30Windows: Detect UACMe (Akagi.exe) execution via PE metadata and image name
Flags Windows processes likely running UACMe (Akagi.exe/Akagi64.exe) using PE metadata and known IMPHASH indicators.
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh242Free2021-08-30Windows: Detect UAC bypass attempts via winsat.exe path parsing from user temp
Flags file activity targeting Temp\system32\winsat.exe (or winmm.dll) under C:\Users\ consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh112Free2021-08-30Windows UAC bypass using NTFS reparse point to place a hijack DLL in Temp
Alerts on file events pointing to a Temp legacy kernel32 DLL within user AppData, consistent with UAC bypass via reparse/DLL targeting.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh267Free2021-08-30Windows UAC Bypass via msconfig Token Modification Dropping pkgmgr.exe from Temp
Alerts on writes to C:\Users\…\AppData\Local\Temp\pkgmgr.exe indicative of msconfig-based UAC bypass staging.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh71Free2021-08-30Windows UAC bypass via IEInstal.exe dropping consent.exe to Temp
Alerts on IEInstal.exe activity writing consent.exe under AppData Local Temp to support a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh372Free2021-08-30Windows UAC Bypass via .NET Code Profiler DLL Hijacking on mmc.exe (pe386.dll in Temp)
Flags creation of Temp\pe386.dll under a user profile, consistent with mmc/.NET code profiler UAC bypass behavior.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh131Free2021-08-30Microsoft Exchange ProxyToken Exploitation via ECP POST and InboxRules NewObject (CVE-2021-33766)
Flags POSTs to Exchange ECP InboxRules endpoints with SecurityToken= that return HTTP 500, indicating ProxyToken exploitation attempts.
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule Team—webserverCritical151Free2021-08-30Windows Process Creation Matching TrustedPath UAC Bypass Directory Mocking Strings
Alerts on Windows processes referencing System32/SysWOW64 paths consistent with TrustedPath UAC bypass directory mocking.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical132Free2021-08-27Exchange Management: Removal of Mailbox Export Request via Remove-MailboxExportRequest
Detects Exchange management removals of mailbox export requests using Remove-MailboxExportRequest with Confirm set to "False".
Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh81Free2021-08-27Windows Security: Suspicious Registry Access to ADHealthAgent Health Service Agent Keys
Detects non-standard processes accessing HKLM\SOFTWARE\Microsoft\ADHealthAgent registry key activity in Windows security logs.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamWindowssecurityMedium60Free2021-08-26Windows Security: Access to Azure AD Health Monitoring Agent Registry Key
Flags suspicious access to the Azure AD Health Monitoring Agent registry key using Windows Security 4656/4663.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamWindowssecurityMedium60Free2021-08-26Google Workspace: Admin audit events where strong authentication is allowed without enforcement (MFA disabled)
Alerts on Google Workspace admin changes that set strong authentication/MFA enforcement to false.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium472Free2021-08-26