Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows Dynamic C# Compilation Generates .cmdline Artifact
Detects Windows file events where dynamic C# compilation produces a .cmdline artefact.
frack113, Huntrule TeamWindowsfile_eventLow417Free2022-01-09PowerShell script exfiltration using Invoke-WebRequest with POST or PUT
PowerShell scripts referencing Invoke-WebRequest with -Method POST/PUT indicate potential data upload behavior.
frack113, Huntrule TeamWindowsps_scriptLow215Free2022-01-07Windows Process Creation: Suspicious systeminfo.exe Execution
Alerts on execution of systeminfo.exe (or sysinfo.exe) via Windows process creation logs for system discovery.
frack113, Huntrule TeamWindowsprocess_creationLow153Free2022-01-01Windows Process Creation: Suspicious reg.exe Query for MachineGuid
Detects reg.exe queries for MachineGuid under SOFTWARE\Microsoft\Cryptography via process creation logs.
frack113, Huntrule TeamWindowsprocess_creationLow445Free2022-01-01Windows adidnsdump Execution via python.exe
Detects python.exe running adidnsdump, a DNS-record enumeration tool used for internal AD recon.
frack113, Huntrule TeamWindowsprocess_creationLow329Free2022-01-01Windows: Suspicious Process Execution of hostname.exe
Flags execution of hostname.exe from process creation events on Windows for discovery activity.
frack113, Huntrule TeamWindowsprocess_creationLow111Free2022-01-01Windows PowerShell Credential Guessing via LDAP using System.Net.NetworkCredential
Detects PowerShell scripts referencing LDAP connection and .NET network credential handling, potentially indicating remote credential access activity.
frack113, Huntrule TeamWindowsps_scriptLow151Free2021-12-27Windows PowerShell Wallpaper Replacement via Registry and SystemParametersInfo
Identifies PowerShell script blocks that modify the HKCU Desktop\WallPaper setting to replace a user’s wallpaper.
frack113, Huntrule TeamWindowsps_scriptLow332Free2021-12-26Windows Process Termination via taskkill.exe Execution
Alerts on taskkill.exe executions that use /f along with /im or /pid to force-terminate targeted processes.
frack113, MalGamy (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationLow70Free2021-12-26Windows PowerShell: Query SMB Shares via Get-SmbShare
Alerts on PowerShell script blocks running Get-SmbShare to discover SMB shares.
frack113, Huntrule TeamWindowsps_scriptLow103Free2021-12-15PowerShell ScriptBlock Enumeration of AD Group Membership and User Attributes (Windows)
Flags PowerShell script blocks querying AD group membership and user details for discovery of privileged directory information.
frack113, Huntrule TeamWindowsps_scriptLow351Free2021-12-15PowerShell Module: Get-SmbShare Used for SMB Share Discovery
Detects PowerShell module usage of Get-SmbShare to enumerate SMB shares across networked systems.
frack113, Huntrule TeamWindowsps_moduleLow465Free2021-12-15PowerShell module enumeration of AD principals via get-ADPrincipalGroupMembership
Flags PowerShell module usage of Get-ADPrincipalGroupMembership and Get-ADUser with -pr -f patterns indicative of AD discovery.
frack113, Huntrule TeamWindowsps_moduleLow234Free2021-12-15Windows process execution of where.exe with browser bookmark database or history artifacts
Alerts on where.exe executions referencing browser history/bookmarks/cookie database artifacts in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow132Free2021-12-13Windows CMD dir /S File and Subfolder Enumeration
Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.
frack113, Huntrule TeamWindowsprocess_creationLow101Free2021-12-13