Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,300 rules
Windows: File creation of C:\program.exe enabling unquoted service path execution
Flags creation of C:\program.exe that can be used to hijack unquoted Windows service binary paths.
frack113, Huntrule TeamWindowsfile_eventHigh388Free2021-12-30Windows Registry Startup: Chrome VPN Extensions Installed via Extension Registry Keys
Flags Windows Registry updates that register VPN/proxy Chrome extensions via the Chrome Extensions update_url key.
frack113, Huntrule TeamWindowsregistry_setHigh91Free2021-12-28Windows Process Creation: Suspicious Kernel Dump via dtrace.exe lkd(0) and syscall:::return
Alerts on Windows process executions of dtrace.exe with command lines consistent with kernel dumping (lkd).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh336Free2021-12-28PowerShell ScriptBlock Requests Kerberos Tickets via IdentityModel Token Assembly
Alerts on PowerShell ScriptBlock text that builds Kerberos ticket requests using KerberosRequestorSecurityToken and .GetRequest().
frack113, Huntrule TeamWindowsps_scriptHigh132Free2021-12-28PowerShell Script Blocks Register Malicious XLL via Office COM Automation on Windows
Detects PowerShell Script Block content that uses COM automation to call .RegisterXLL for an Office XLL add-in.
frack113, Huntrule TeamWindowsps_scriptHigh414Free2021-12-28Windows Suspicious File Downloads from Outlook/OneNote Attachment Domains via Command-Line
Flags Windows command-line downloads using curl/wget or PowerShell from Outlook/OneNote attachment domains.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2021-12-27Windows Process Execution of Hashcat.exe for Password Cracking
Alerts on Hashcat.exe launched with cracking-focused flags targeting an offline SAM-derived dataset.
frack113, Huntrule TeamWindowsprocess_creationHigh409Free2021-12-27Windows: Findstr searches GPP cpassword in SYSVOL XML
Alerts when Windows findstr/find searches SYSVOL XML files for GPP cpassword.
frack113, Huntrule TeamWindowsprocess_creationHigh417Free2021-12-27Windows PowerShell Copies a DLL into System32 or SysWOW64
Flags PowerShell Copy-Item targeting Windows\System32 or Windows\SysWOW64 for file placement.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2021-12-27Windows schtasks.exe /disable Used to Disable Security-Critical Scheduled Tasks
Flags schtasks.exe executions using /disable against security-critical Windows scheduled task paths.
frack113, Nasreddine Bencherchali (Nextron Systems), X__Junior, Huntrule TeamWindowsprocess_creationHigh71Free2021-12-26Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh70Free2021-12-22Windows: Detect Computer Account Rename to Non-Standard Name Missing Trailing '$'
Alerts on Windows 4781 computer account renames where the new name lacks the '$' suffix.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh82Free2021-12-22Suspicious Windows Process Creation as SYSTEM User with Likely Credential/Defense Evasion Commands
Flags SYSTEM-context process executions on Windows that include suspicious tool names or command-line patterns such as PowerShell/Mimikatz indicators.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindowsprocess_creationHigh122Free2021-12-20Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo
Alerts on sqlcmd.exe running a query targeting the VeeamBackup dbo Credentials table to dump sensitive credentials.
frack113, Huntrule TeamWindowsprocess_creationHigh343Free2021-12-20Windows: Detect sc.exe Service Creation with DACL Modification (sdset DCLCWPDTSD)
Alerts on sc.exe sdset usage with DCLCWPDTSD, suggesting permission changes to hide or impede service removal.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh60Free2021-12-20