Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,291 rules
PowerShell Script Block WinAPI Calls Indicative of Injection or Token Abuse (Windows)
Detects PowerShell ScriptBlocks containing WinAPI function-name combinations consistent with injection and token manipulation.
Nasreddine Bencherchali (Nextron Systems), Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh173Free2020-10-06Windows UAC Bypass via dism.exe Loading Fake dismcore.dll
Alerts when dism.exe loads a dismcore.dll that is not the expected System32 Dism DLL.
oscd.community, Dmitry Uchakin, Huntrule TeamWindowsimage_loadHigh404Free2020-10-06Windows Time Travel Debugging DLL Loads (ttdrecord/ttdwriter/ttdloader)
Flags Windows image loads of Time Travel Debugging Utility DLLs (tdrecord/tdwriter/tdloader), often abused for stealthy credential dumping.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsimage_loadHigh416Free2020-10-06Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
oscd.community, Natalia Shornikova, Huntrule TeamWindowscreate_remote_threadHigh215Free2020-10-06PowerShell Script Execution via Windows Service Creation (Service Control Manager)
Flags service creation/start events where the service ImagePath references PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowssystemHigh463Free2020-10-06Windows Service Creation of PowerShell/Pwsh Scripts (Security EID 4697)
Alerts on service creation events where the service executable name includes powershell or pwsh.
oscd.community, Natalia Shornikova, Huntrule TeamWindowssecurityHigh182Free2020-10-06Non-privileged reg.exe or PowerShell registry service configuration changes on Windows
Flags non-admin reg.exe or PowerShell activity targeting service registry configuration paths on Windows.
Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh439Free2020-10-05Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Alerts when Windows process command lines include Hydra -u/-p parameters with USER/PASS placeholders.
Vasiliy Burov, Huntrule TeamWindowsprocess_creationHigh151Free2020-10-05Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)
Flags HKCU DelegateExecute registry changes for COM hijack style persistence under the Folder shell open command.
Omkar Gudhate, Huntrule TeamWindowsregistry_setHigh121Free2020-09-27Detect Wannacry killswitch DNS queries to hardcoded domains
Flags DNS lookups for known WannaCry killswitch domain strings and variants.
Mike Wade, Huntrule TeamNetworkdnsHigh131Free2020-09-16Windows NetLogon Secure Channel Connection Allowed for Vulnerable Client
Alerts on Windows NetLogon ETW events indicating an allowed secure channel connection (Event ID 5829).
NVISO, Huntrule TeamWindowssystemHigh102Free2020-09-15Windows Defender Windefend AMSI Detection (Event ID 1116)
Flags Windows Defender AMSI detections via windefend Event ID 1116 with SourceName set to AMSI.
Bhabesh Raj, Huntrule TeamWindowswindefendHigh70Free2020-09-14Windows Process Creation: MpCmdRun.EXE Used to Download Files via DownloadFile url
Alerts when MpCmdRun.exe is executed with DownloadFile and url, indicating Defender utility file download behavior.
Matthew Matchen, Huntrule TeamWindowsprocess_creationHigh191Free2020-09-04Windows Process Creation Indicators for Snatch Ransomware Word Document Droppers
Alerts on Windows process command lines showing instant safe-mode shutdown/reboot and stopping SuperBackupMan service.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2020-08-26Zeek: Public RDP Connections from Non-Private IPv4/IPv6 Ranges
Alert on Zeek-observed RDP connections originating from non-excluded IP ranges, suggesting external accessibility.
Josh Brower @DefensiveDepth, Huntrule TeamZeekrdpHigh235Free2020-08-22