Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows AppCompatFlags Store New Application Registry Entries
Alerts on new writes to the AppCompat Compatibility Assistant store registry path, indicating first-time application behavior.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setInformational3410Free2020-05-02Windows Registry Deletion of Shell Open Command COM Hijacking Key Paths
Flags registry deletions of \shell\open\command paths that may indicate removal of COM hijacking execution entries.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_deleteMedium103Free2020-05-02Windows sdclt.exe Spawned with High Integrity (Possible UAC Bypass)
Alerts on sdclt.exe launching as High integrity, indicating possible elevated execution consistent with UAC bypass attempts.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium92Free2020-05-02Windows Process Creation: .NET ETW Logging Environment Variables Set via Command Line
Flags process command lines setting COMPlus_ETWEnabled/COMPlus_ETWFlags, potentially impairing ETW logging for .NET.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationHigh336Free2020-05-02Windows sdclt.exe Child Process Creation
Alerts when sdclt.exe launches a child process, a behavior consistent with abused Windows binaries in escalation chains.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium273Free2020-05-02Windows rundll32 WebDAV Client Execution (davclnt.dll DavSetCookie)
Flags svchost.exe spawning rundll32.exe to run davclnt.dll,DavSetCookie, consistent with WebDAV client execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium60Free2020-05-02PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Flags Windows command lines containing Get-Clipboard, indicating potential clipboard data collection via PowerShell.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2020-05-02Windows PowerShell Get-Clipboard Command Execution
Flags PowerShell activity that includes the Get-Clipboard command, which may be used to collect clipboard contents.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleMedium289Free2020-05-02PowerShell Decompress via Expand-Archive
Alerts on PowerShell usage of Expand-Archive, a common decompression step attackers may use to unpack files.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleInformational93Free2020-05-02Windows Startup Directory File Writes for Persistence
Alerts on file writes into the Windows Startup folder that may indicate user-level persistence.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventMedium2410Free2020-05-02Windows File Deletion Using Sysinternals SDelete (SDelete rename suffixes)
Flags Windows file deletions targeting filenames ending in .AAA or .ZZZ consistent with SDelete-style artifact removal.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_deleteMedium94Free2020-05-02Zeek: Detect WebDAV User-Agent with HTTP PUT to local or RFC1918 addresses
Flags Zeek HTTP PUT requests with a WebDAV User-Agent that target non-excluded network addresses.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamZeekhttpLow153Free2020-05-02Windows Image Load of System.Drawing.ni.dll
Alerts when a Windows process loads System.Drawing.ni.dll, which may indicate visual data collection activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadLow50Free2020-05-02Windows PFX File Creation From File Events
Flags Windows file events where a .pfx (certificate + private key) is created, excluding a few common benign locations.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventLow50Free2020-05-02Windows findstr Launches .lnk via Command Line
Flags find.exe or findstr.exe processes whose command lines end with a .lnk file.
Trent Liffick, Huntrule TeamWindowsprocess_creationMedium71Free2020-05-01