Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,301 rules
Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Alerts on creation of ntds.dit on Windows when the creator process image/path is uncommon or located in suspicious directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh131Free2022-01-11Windows WScript/CScript File Write With Script Extensions to Temp or Startup Paths
Alerts when WScript/CScript writes script files (.js/.vbs/.wsf/.wsh, etc.) into common temp or Startup directories.
Tim Shelton, Huntrule TeamWindowsfile_eventHigh459Free2022-01-10Windows ChromeLoader Execution via Scheduled Task and Hidden PowerShell Launch
Flags PowerShell-launched chrome.exe that uses --load-extension from local AppData Chrome paths for ChromeLoader-style execution.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh92Free2022-01-10Windows: AppCmd disables IIS HTTP logging via dontLog=true
Flags appcmd.exe commands that disable IIS HTTP logging by setting httplogging to dontLog:true.
frack113, Huntrule TeamWindowsprocess_creationHigh353Free2022-01-09PowerShell DNSExfiltrator command usage (DNSExfiltration)
Detects PowerShell use of Invoke-DNSExfiltrator for DNS/DoH-based exfiltration based on Script Block Logging content.
frack113, Huntrule TeamWindowsps_scriptHigh131Free2022-01-07Windows Registry: Detect windir Environment Key Changes for SilentCleanup UAC Bypass
Detects non-default Environment\windir registry changes commonly used to facilitate SilentCleanup UAC bypass.
frack113, Nextron Systems, Huntrule TeamWindowsregistry_setHigh3110Free2022-01-06Registry Modification for UAC Bypass via Event Viewer Command Handler (Windows)
Monitors registry value changes to the Event Viewer command handler path indicative of a UAC bypass attempt on Windows.
frack113, Huntrule TeamWindowsregistry_setHigh133Free2022-01-05Windows Registry: Detect DelegateExecute UAC bypass via TargetObject path
Alerts on registry set events targeting \open\command\DelegateExecute with empty Details, consistent with a UAC bypass attempt.
frack113, Huntrule TeamWindowsregistry_setHigh4310Free2022-01-05Windows Process Creation: Pypykatz Credential Dumping via Registry Parsing
Alerts when pypykatz is run with "live" and "registry" parameters to extract credential data from local SAM-related artifacts.
frack113, Huntrule TeamWindowsprocess_creationHigh391Free2022-01-05Windows: Uncommon format.com File System Load via /fs parameter
Alerts on format.com executions with atypical /fs: parameters, which may indicate defense-evasion use of Windows utilities.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-01-04Windows Process Creation: createdump.exe Dumping Memory with Full and Name Flags
Flags and .dmp output usage indicate createdump.exe dumping process memory on Windows.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh268Free2022-01-04Windows Process Creation: Headless Chromium Download via dump-dom
Flags headless Chromium browser executions using dump-dom and an http URL on Windows, indicative of stealthy remote content retrieval.
Sreeman, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-01-04Windows Registry: RDP PortNumber changed from default 3389
Alerts on Windows registry updates to the RDP-Tcp PortNumber when it changes away from default 3389.
frack113, Huntrule TeamWindowsregistry_setHigh132Free2022-01-01SharpHound RPC Firewall Recon: Remote Mapping and Group Membership Enumeration
Alerts on RPC Firewall EventID 3 for SharpHound-style discovery RPC calls to interface UUID with OpNum 12.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh112Free2022-01-01SharpHound Account Recon via RPC Firewall Block (OpNum 2, Interface UUID)
Alerts on RPC Firewall EventID 3 with the Interface UUID and OpNum used by SharpHound for account discovery.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh1710Free2022-01-01