Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,302 rules
Windows Suspicious Parent Processes: Unusual Child Creation by System Utilities
Alerts when predefined suspicious Windows parent executables spawn unusual or unrecognized child processes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2022-03-21Windows Service Control Manager: HackTool Service Installation or Start via Suspicious Service Names
Detects Windows service creation/start events tied to hacktool-like service names or ImagePath indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh362Free2022-03-21Windows Scheduled Task Backdoor Execution via cmd.exe or PowerShell (System EventID /create /delete)
Flags cmd.exe/powershell.exe command lines that create a System/EventID-based scheduled task to run a payload.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh233Free2022-03-21Windows Service Installation via Scripted ImagePath Indicators (Event 7045)
Identifies suspicious Windows service installations that embed script host execution via Event ID 7045 ImagePath patterns.
pH-T (Nextron Systems), Huntrule TeamWindowssystemHigh446Free2022-03-18Windows Service Installation with Suspicious ProgramData/Root Executable Image Paths
Flags Windows service installs (Event 7045) that reference suspicious EXE paths in ProgramData or directly under C:\.
pH-T (Nextron Systems), Huntrule TeamWindowssystemHigh93Free2022-03-18Windows Service Installation with PowerShell Download and Hidden Execution
Alerts on Windows service creation (7045) with ImagePath patterns indicating hidden/staged command execution.
pH-T (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh152Free2022-03-18Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Flags web server processes spawning child commands consistent with credential dumping, exfiltration, and privilege changes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-03-17Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh133Free2022-03-16Windows schtasks.exe Create Executes File from AppData\Local
Alerts on schtasks.exe creating tasks that run payloads from C:\Users\<user>\AppData\Local.
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh196Free2022-03-15Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh215Free2022-03-12Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh327Free2022-03-11Windows Suspicious UltraVNC Command Line With Auto-Reconnect Flags
Alerts on UltraVNC execution using -autoreconnect with -connect and -id in the Windows command line.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh151Free2022-03-04PowerShell Base64 Encoded MpPreference Command Lines for Windows Defender Modification
Detects PowerShell Base64 command lines referencing Add-MpPreference/Set-MpPreference to modify Microsoft Defender AV settings.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh147Free2022-03-04Windows PowerShell: Disable Microsoft Defender Scanning via Set-MpPreference
Flags PowerShell commands that disable Microsoft Defender scanning/protection settings using Set-MpPreference, including encoded variants.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh308Free2022-03-03