Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,286 rules
Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh91Free2019-10-22Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Flags reg.exe command lines exporting or saving HKLM registry hives tied to SAM, SYSTEM, and SECURITY.
Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh3510Free2019-10-22Windows Process Execution Matching SILENTTRINITY Stager Metadata (st2stager)
Flags Windows process creation events containing "st2stager" in PE metadata, indicating SILENTTRINITY stager activity.
Aleksey Potapov, oscd.community, Huntrule TeamWindowsprocess_creationHigh169Free2019-10-22Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Flags Windows processes whose command lines contain Mimikatz names and credential-dumping module/function arguments.
Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh123Free2019-10-22Windows: Detect esentutl.exe Copying Sensitive Credential Files via VSS
Alerts on esentutl.exe VSS usage and command lines referencing SAM/SECURITY/SYSTEM or ntds.dit copy targets.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh122Free2019-10-22Windows Volume Shadow Copy Symlink Creation Using mklink
Flags Windows mklink commands that reference HarddiskVolumeShadowCopy to create symlinks.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh123Free2019-10-22Windows: Detect sc.exe Service Config binPath Changes to Suspicious Commands/Paths
Alerts when sc.exe updates a service binPath to point at suspicious commands or commonly abused directories.
Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2019-10-21Suspicious Crypto Miner User Agents in Proxy Logs
Flags proxy requests with User-Agent prefixes tied to XMRig or CCMiner crypto miners.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh267Free2019-10-21Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Alerts on Linux process command lines containing ' -u#' indicative of sudo CVE-2019-14287 exploitation attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh175Free2019-10-15Windows OpenWith.exe Launches Another Binary via /c
Flags Windows OpenWith.exe executions that include '/c', indicating it launched another binary.
Beyu Denis, oscd.community (rule), @harr0ey (idea), Huntrule TeamWindowsprocess_creationHigh42Free2019-10-12Windows Devtoolslauncher.exe LaunchForDeploy Executes a Specified Binary
Alerts when devtoolslauncher.exe runs with LaunchForDeploy, indicating it may launch another binary on Windows.
Beyu Denis, oscd.community (rule), @_felamos (idea), Huntrule TeamWindowsprocess_creationHigh337Free2019-10-12PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh60Free2019-10-08PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh297Free2019-10-08Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders
Alerts on registry Run key writes originating from Downloads or temporary Outlook/IE directories on Windows.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poude (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh113Free2019-10-01Suspicious Windows Program Execution from Outlook Temporary Internet Files Folder
Alerts on process executions whose image path points to Outlook temporary files (Content.Outlook).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2019-10-01