Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_classic_provider_startHigh403Free2021-06-07Windows Sysmon Configuration Event Where Sysmon Stops
Alert on Sysmon status showing a stop event concurrent with a Sysmon configuration state change.
frack113, Huntrule TeamWindowssysmon_statusHigh447Free2021-06-04Windows Sysmon error events indicating service configuration update failures
Flags Windows Sysmon errors for failed service configuration/driver update attempts that may indicate tampering.
frack113, Huntrule TeamWindowssysmon_errorHigh172Free2021-06-04Windows Process Creation: SDelete Used for File Overwrite
Alerts when sdelete.exe runs in a way consistent with file overwrite to impede forensic recovery.
frack113, Huntrule TeamWindowsprocess_creationHigh296Free2021-06-03Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
frack113, Huntrule TeamWindowsps_classic_startHigh369Free2021-06-03Windows Rundll32 Used to Start Cobalt Strike DLL Load via StartW
Alerts on rundll32.exe command lines that include a .dll and StartW function, consistent with Cobalt Strike DLL loading.
Wojciech Lesicki, Huntrule TeamWindowsprocess_creationHigh163Free2021-06-01Nginx service core dump after worker crash (signal 6)
Flags Nginx worker crashes that end with signal 6 core dumps, which may indicate serious issues or exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWebnginxHigh192Free2021-05-31Windows rundll32.exe Started Without Command-Line Parameters
Alerts on Windows process launches of rundll32.exe with no parameters, excluding likely benign parent paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-05-27Windows: regedit.exe launched with TrustedInstaller or Process Hacker parent
Alerts when regedit.exe is launched by TrustedInstaller.exe or ProcessHacker.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh394Free2021-05-27Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Flags Windows service installs for ProcessHacker-prefixed services running as LocalSystem.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh231Free2021-05-27Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssecurityHigh133Free2021-05-26Linux PAM TTY Audit Enabling via /etc/pam.d Modification
Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.
Pawel Mazur, Huntrule TeamLinuxauditdHigh152Free2021-05-24Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Flags indicating PsExec/PAExec-style execution as LOCAL SYSTEM using cmd/powershell/pwsh in process command lines.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4110Free2021-05-22Windows Process Creation: Renamed PAExec Application Execution
Flags Windows executions of a renamed PAExec binary using process metadata and known IMPHASH values.
Florian Roth (Nextron Systems), Jason Lynch, Huntrule TeamWindowsprocess_creationHigh162Free2021-05-22Wazuh CVE-2021-26814 RCE Exploitation via Directory Traversal in Web Requests
Detects Wazuh-related web requests attempting path traversal through the /manager/files query parameter.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh235Free2021-05-22