Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows MSExchange Transport Agent Installation via Install-TransportAgent
Flags Exchange Transport Agent installation attempts using the Install-TransportAgent command in MSExchange management telemetry.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsmsexchange-managementMedium503Free2021-06-08Windows AMSI Provider Registry Key Deletion (HKLM\Software\Microsoft\AMSI)
Alerts on deletion of AMSI provider registry key entries under HKLM\Software\Microsoft\AMSI, potentially indicating AMSI inspection impairment.
frack113, Huntrule TeamWindowsregistry_deleteHigh172Free2021-06-07PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_classic_provider_startHigh403Free2021-06-07Windows Sysmon Configuration Event Where Sysmon Stops
Alert on Sysmon status showing a stop event concurrent with a Sysmon configuration state change.
frack113, Huntrule TeamWindowssysmon_statusHigh437Free2021-06-04Windows Sysmon error events indicating service configuration update failures
Flags Windows Sysmon errors for failed service configuration/driver update attempts that may indicate tampering.
frack113, Huntrule TeamWindowssysmon_errorHigh172Free2021-06-04Windows Process Creation: SDelete Used for File Overwrite
Alerts when sdelete.exe runs in a way consistent with file overwrite to impede forensic recovery.
frack113, Huntrule TeamWindowsprocess_creationHigh296Free2021-06-03Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
frack113, Huntrule TeamWindowsps_classic_startHigh369Free2021-06-03Windows Rundll32 Loads DLL Export StartNodeRelay (F-Secure C3)
Flags rundll32.exe launching a DLL that references the StartNodeRelay export in its command line.
Alfie Champion (ajpc500), Huntrule TeamWindowsprocess_creationCritical435Free2021-06-02Windows Rundll32 Used to Start Cobalt Strike DLL Load via StartW
Alerts on rundll32.exe command lines that include a .dll and StartW function, consistent with Cobalt Strike DLL loading.
Wojciech Lesicki, Huntrule TeamWindowsprocess_creationHigh143Free2021-06-01Nginx service core dump after worker crash (signal 6)
Flags Nginx worker crashes that end with signal 6 core dumps, which may indicate serious issues or exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWebnginxHigh192Free2021-05-31Windows Security Event 4663: ISO CD-ROM device mount activity
Alerts on Windows file-access events consistent with ISO mounting by activity under \\Device\\CdRom.
Syed Hasan (@syedhasan009), Huntrule TeamWindowssecurityMedium131Free2021-05-29Windows rundll32.exe Started Without Command-Line Parameters
Alerts on Windows process launches of rundll32.exe with no parameters, excluding likely benign parent paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-05-27Windows: regedit.exe launched with TrustedInstaller or Process Hacker parent
Alerts when regedit.exe is launched by TrustedInstaller.exe or ProcessHacker.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh394Free2021-05-27Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Flags Windows service installs for ProcessHacker-prefixed services running as LocalSystem.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh231Free2021-05-27Windows: Rclone Configuration File Creation via rclone config path
Alerts on creation of rclone config files under a Windows user profile path.
Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsfile_eventMedium183Free2021-05-26