Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,311 rules
Windows Registry Tampering: Attachment Manager Associations Default File Type Risk and LowRiskFileTypes
Flags Windows registry changes to Attachment Manager associations that set DefaultFileTypeRisk and modify LowRiskFileTypes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh179Free2022-08-01Windows Registry Change Disabling WinDefend Service (WinDefend Start=4)
Flags registry changes that set WinDefend service Start to 0x4, indicating potential defensive impairment.
Ján Trenčanský, frack113, AlertIQ, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh412Free2022-08-01Windows Registry AutoLogger Session Disable/Start Tampering via Event Log Targets
Alerts when registry changes disable or stop AutoLogger sessions for EventLog-* or Defender by setting Enabled/Start to 0x0.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh2610Free2022-08-01Windows reg.exe deletes service registry keys using the delete flag
Alerts on reg.exe command lines that delete entries under the Windows services registry path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-08-01Windows Defender mpclient.dll Side-loading: MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when MpCmdRun.exe or NisSrv.exe runs from non-default directories, a common indicator of possible mpclient.dll sideloading.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh394Free2022-08-01Windows ISO File Creation in User Temp and Outlook Cache Folders
Alerts on creation of .iso files in Windows AppData temp or Outlook cache paths.
"@sam0x90, Huntrule Team"Windowsfile_eventHigh91Free2022-07-30Windows DLL Search Order Hijack via Space in System Directory Paths
Alerts on .dll events targeting Windows system paths with an extra space, indicative of DLL search order hijacking.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh346Free2022-07-30Windows Sysmon Driver Altitude Registry Changes
Identifies registry writes that change the Sysmon instance altitude value, which can disrupt Sysmon loading at boot.
B.Talebi, Huntrule TeamWindowsregistry_setHigh123Free2022-07-28Windows schtasks Scheduled Task Create/Modify Running as SYSTEM
Alerts on Windows schtasks task create/modify commands that set the run account to NT AUTHORITY\SYSTEM.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh195Free2022-07-28Windows: Suspicious Scheduled Task Modification via schtasks /Change /TN
Flags schtasks.exe executions that modify existing scheduled tasks (/Change /TN) using suspicious locations and command-line payload tooling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh438Free2022-07-28Azure Audit Logs: Admin-initiated App Role Assignments and Privileged Delegated Permissions
Alerts on Azure audit events where an admin grants app roles to a service principal, enabling privileged application access.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh90Free2022-07-28Azure audit logs: Delegated highly privileged permissions granted for all users
Alerts on Azure audit log events where delegated permissions are granted to all users.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh90Free2022-07-28Windows: WinRing0 Driver Load via Image Hash and File Name Match
Alerts on Windows driver loads matching WinRing0 modules by IMPhash or expected WinRing0 filenames.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh162Free2022-07-26Windows: Detect SelectMyParent PPID Spoofing Tool Execution
Flags SelectMyParent.exe process creation with PPID spoofing command-line and metadata indicators on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-07-23Windows Registry: Detect DLLPathOverride Persistence in ContentIndex Natural Language
Alerts on Windows registry changes to ContentIndex Natural Language DLLPathOverride values tied to SearchIndexer.exe persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh318Free2022-07-21