Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,522 rules
Windows Setup16.EXE Execution Triggered by Custom .LST File
Flags Windows Setup16.EXE being invoked with ' -m ' from its system parent process, potentially tied to custom .lst-driven execution.
frack113, Huntrule TeamWindowsprocess_creationMedium203Free2024-12-01Windows Suspicious ShellExec_RunDLL via SHELL32.DLL Ordinal in Parent Command Line
Alert on Windows process starts where parent command line invokes SHELL32.DLL ShellExec_RunDLL using a matched ordinal and spawns suspicious binaries.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh349Free2024-12-01Windows File Event: Detect RTLO Filename Extension Spoofing
Flags Windows filenames containing U+202E plus reversed extension strings that indicate potential extension spoofing.
Jonathan Peters (Nextron Systems), Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh202Free2024-11-17Windows Network Connections to azurefd.net Excluding Common Browsers and Known Front Door Hostnames
Flags Windows connections to azurefd.net that aren’t from common browsers/search or known benign Azure Front Door domains.
Isaac Dunham, Huntrule TeamWindowsnetwork_connectionMedium120Free2024-11-07Windows Registry RunMRU PowerShell or WMIC Execution Command Indicators
Alerts on RunMRU registry entries showing PowerShell (encoding/invocation) or WMIC shadowcopy/process call usage.
Ahmed Farouk, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh191Free2024-11-01Windows Command Execution via Run Dialog (RunMRU) Registry Entries
Flags suspicious Run dialog command entries by matching RunMRU registry key updates on Windows.
Ahmed Farouk, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setLow110Free2024-11-01Windows Security 4663: Uncommon Processes Access Browser Credential Store Files
Flags 4663 file access to browser credential stores (Chromium/Firefox) by processes outside common system/benign paths.
Daniel Koifman (@Koifsec), Nasreddine Bencherchali, Huntrule TeamWindowssecurityLow110Free2024-10-21Windows IIS module removal event (IIS-configuration EventID 29)
Detects removal of an IIS module from Windows IIS configuration events (Event ID 29).
Nasreddine Bencherchali, Huntrule TeamWindowsiis-configurationLow153Free2024-10-06Windows IIS Configuration: New Module Added to /system.webServer/modules
Flags IIS configuration events where a new module is added under /system.webServer/modules.
frack113, Huntrule TeamWindowsiis-configurationMedium418Free2024-10-06IIS HTTP Logging Disabled via dontLog Configuration Change (Windows)
Alerts on IIS configuration updates that disable HTTP logging by setting dontLog to true for successful requests.
frack113, Huntrule TeamWindowsiis-configurationHigh442Free2024-10-06Windows IIS Configuration: Disable ETW Logging/Processing via logTargetW3C Change
Identifies IIS configuration edits that remove/disable ETW logging or processing for W3C log targeting.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsiis-configurationMedium301Free2024-10-06Windows MeshAgent remote command execution via cmd.exe or PowerShell child processes
Flags cmd.exe or PowerShell spawned by meshagent.exe on Windows, indicating potential remote command execution.
"@Kostastsale, Huntrule Team"Windowsprocess_creationMedium505Free2024-09-22Windows Process Initiated Connections to .btunnel.co.in Domains
Flags initiated outbound connections to .btunnel.co.in domains from a Windows host.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium172Free2024-09-13Windows: GPO Modification Adds Startup/Logon Script References
Flags GPO changes that add startup/logon scripts (SYSVOL scripts.ini) for user or computer targets using Windows directory/audit events.
Elastic, Josh Nickels, Marius Rothenbücher, Huntrule TeamWindowssecurityMedium173Free2024-09-06Windows Security: Group Policy Object modification adds privileges to user accounts
Alerts on Windows GPO attribute changes that correspond to adding privileges or making users local admins.
Elastic, Josh Nickels, Marius Rothenbücher, Huntrule TeamWindowssecurityMedium141Free2024-09-04