Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Security: Detect Obfuscated PowerShell IEX Invocation via ServiceFileName Patterns (Event ID 4697)
Alerts on EventID 4697 instances where ServiceFileName matches obfuscated IEX-style PowerShell invocation patterns consistent with Invoke-Obfuscation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowssecurityHigh141Free2019-11-08Windows: Detect netsh.exe Commands Disabling Firewall
Flags netsh.exe executions that include command-line patterns used to disable Windows firewall.
Fatih Sirin, Huntrule TeamWindowsprocess_creationMedium133Free2019-11-01Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Flags PowerShell ScriptBlockText that combines Empire process-control indicators with dnscat DNS tunneling commands.
Alina Stepchenkova, Group-IB, oscd.community, Huntrule TeamWindowsps_scriptCritical71Free2019-11-01Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Alerts on Windows named pipe creations matching credential dumping tool pipe names.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowspipe_createdCritical375Free2019-11-01Windows Credential Dump Tool Artifacts Written to Disk via File Events
Detects Windows file creation where the target filename contains or ends with known credential-dump tool or output names.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsfile_eventHigh257Free2019-11-01Windows Security: Suspicious AccessMask/AccessList Requested on LSASS (lsass.exe) Handle
Flags processes requesting potentially credential-dumping-related access to LSASS based on Security Event 4656/4663.
Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update), Huntrule TeamWindowssecurityMedium184Free2019-11-01Windows Security: Suspicious Local Account Created with ANONYMOUS LOGON SamAccountName
Alerts on Windows local account creation where the new SamAccountName contains “ANONYMOUS” and “LOGON”.
James Pemberton / @4A616D6573, Huntrule TeamWindowssecurityHigh40Free2019-10-31Windows PowerShell Script Execution from Alternate Data Stream (ADS)
Flags PowerShell processes using Get-Content -Stream to execute or retrieve script content from an ADS.
Sergey Soldatov, Kaspersky Lab, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2019-10-30Windows Process Creation Matching Mustang Panda Dropper Command-Line and winwsh.exe
Alerts on Windows process creation with temp-based wtaks/winwsh execution and script-launch command-line parameters.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationHigh103Free2019-10-30Windows process creation: Suspicious Dtrack RAT ping and network recon commands
Alerts on Windows command-line reconnaissance patterns resembling Dtrack RAT activity.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical82Free2019-10-30Windows Image Load: Unsigned dbghelp.dll/dbgcore.dll Loaded by Suspicious Process
Alerts on unsigned loading of dbghelp.dll/dbgcore.dll, often associated with memory dump creation and credential-access workflows.
Perez Diego (@darkquassar), oscd.community, Ecco, Huntrule TeamWindowsimage_loadHigh348Free2019-10-27Windows Remote Thread Creation Triggered by Uncommon Source Images
Detects remote thread creation on Windows when the SourceImage is one of several uncommon executables.
Perez Diego (@darkquassar), oscd.community, Huntrule TeamWindowscreate_remote_threadMedium404Free2019-10-27Windows Remote Thread Creation from Uncommon Parent Image
Alerts on remote thread creation on Windows when the source executable is rare, with exclusions for known benign image pairings.
Perez Diego (@darkquassar), oscd.community, Huntrule TeamWindowscreate_remote_threadHigh342Free2019-10-27Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Alert on Windows executions where a SYSTEM-integrity child is spawned by a LOCAL SERVICE or NETWORK SERVICE parent, excluding a specific rundll32 pattern.
Teymur Kheirkhabarov, Roberto Rodriguez (@Cyb3rWard0g), Open Threat Research (OTR), Huntrule TeamWindowsprocess_creationHigh209Free2019-10-26Windows: sc.exe Service Configuration Changed by Medium-Integrity Users
Alerts on sc.exe runs from Medium-integrity users that include service config/binPath or failure command changes.
Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh111Free2019-10-26