Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,296 rules
Windows Registry UAC Bypass via winsat.exe LowerCaseLongPath and UACMe Path Parsing
Matches registry writes that reference winsat.exe using a LowerCaseLongPath construction consistent with UAC bypass path parsing.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh169Free2021-08-30Windows Process Creation: UAC Bypass via winsat.exe Path Parsing
Alerts on elevated processes spawned by Temp-path winsat.exe with system32 winsat command-line content.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh434Free2021-08-30Windows UAC Bypass via NTFS Reparse Point: wusa.exe DLL Hijacking Process Behavior
Alerts on high-integrity wusa.exe launched from Temp update.msu with a dism.exe parent showing DismHost activity.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2021-08-30Windows UAC Bypass via msconfig Token Modification (msconfig.exe -5) Process Creation
Flags msconfig.exe invoked with -5 from a Temp pkgmgr.exe parent under elevated integrity levels, indicating a possible UAC bypass.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-08-30Windows UAC Bypass via IEInstal.exe Launching consent.exe from Temp with Elevated Integrity
Alerts on elevated consent.exe spawned by ieinstal.exe from Temp, indicating a possible Windows UAC bypass chain.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2021-08-30Windows UAC Bypass via DismHost.exe DLL Hijacking
Flags DismHost.exe executions from AppData\Local\Temp running as High/System integrity, consistent with UAC bypass via DLL hijacking.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-30Windows UAC Bypass via Disk Cleanup cleanmgr.exe run from Scheduled Task
Flags scheduled-task executions of cleanmgr.exe with disk-cleanup parameters running at high/System integrity.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh159Free2021-08-30Windows: Detect UACMe (Akagi.exe) execution via PE metadata and image name
Flags Windows processes likely running UACMe (Akagi.exe/Akagi64.exe) using PE metadata and known IMPHASH indicators.
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh252Free2021-08-30Windows: Detect UAC bypass attempts via winsat.exe path parsing from user temp
Flags file activity targeting Temp\system32\winsat.exe (or winmm.dll) under C:\Users\ consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh112Free2021-08-30Windows UAC bypass using NTFS reparse point to place a hijack DLL in Temp
Alerts on file events pointing to a Temp legacy kernel32 DLL within user AppData, consistent with UAC bypass via reparse/DLL targeting.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh267Free2021-08-30Windows UAC Bypass via msconfig Token Modification Dropping pkgmgr.exe from Temp
Alerts on writes to C:\Users\…\AppData\Local\Temp\pkgmgr.exe indicative of msconfig-based UAC bypass staging.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh71Free2021-08-30Windows UAC bypass via IEInstal.exe dropping consent.exe to Temp
Alerts on IEInstal.exe activity writing consent.exe under AppData Local Temp to support a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh372Free2021-08-30Windows UAC Bypass via .NET Code Profiler DLL Hijacking on mmc.exe (pe386.dll in Temp)
Flags creation of Temp\pe386.dll under a user profile, consistent with mmc/.NET code profiler UAC bypass behavior.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh141Free2021-08-30Exchange Management: Removal of Mailbox Export Request via Remove-MailboxExportRequest
Detects Exchange management removals of mailbox export requests using Remove-MailboxExportRequest with Confirm set to "False".
Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh81Free2021-08-27Windows Registry UAC Bypass Attempt via Windows Media Player osk.exe AppCompatFlags
Identifies registry AppCompatFlags entries for Windows Media Player osk.exe that may indicate a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2021-08-23