Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,454 rules
Windows: Uncommon Child Processes Spawned by Addinutil.exe
Alerts when Addinutil.exe launches an uncommon child process, indicating potential proxy execution abuse.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium273Free2023-09-18Windows AddInUtil.exe Executed with Suspicious AddInRoot or PipelineRoot Parameters
Alerts on AddInUtil.exe runs using uncommon AddInRoot/PipelineRoot values targeting Temp, Desktop, Downloads, or public user paths.
Nasreddine Bencherchali (Nextron Systems), Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationHigh102Free2023-09-18Windows network connections initiated by AddinUtil.exe
Alerts on network connections initiated by Addinutil.exe, which is uncommon for this utility on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsnetwork_connectionHigh431Free2023-09-18Microsoft 365 Audit: New Federated Domain Added
Alerts on Microsoft 365 audit events indicating a new federated domain was added.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditMedium113Free2023-09-18Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditHigh416Free2023-09-18Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths
Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-09-15Windows Diskshadow Script Mode Executes Script File with Uncommon .txt Extension
Alerts when diskshadow.exe runs with -s script mode and the script path/command includes an uncommon extension like .txt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium341Free2023-09-15Suspicious Child Process Spawned by Diskshadow.exe (Windows Process Creation)
Alerts on process creation where Diskshadow.exe spawns certutil, cscript, mshta, PowerShell, regsvr32, rundll32, or wscript.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium110Free2023-09-15Windows Diskshadow.exe Child Process Execution
Alerts when Diskshadow.exe is the parent process of a newly created process on Windows.
Harjot Singh @cyb3rjy0t, Huntrule TeamWindowsprocess_creationMedium100Free2023-09-15Windows File Access to .reg and .hive Backups by Uncommon Applications
Alerts on access to .hive/.reg files from less-common application paths on Windows.
frack113, Huntrule TeamWindowsfile_accessLow80Free2023-09-15Azure Entra PIM Alerts: Too Many Global Administrators Assigned to Tenant
Alerts when Azure PIM reports an overabundance of Global Administrator role assignments in a tenant.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh103Free2023-09-14Azure AD PIM Redundant Assignment Alert When Privileged Role Not Used
Alerts on Azure PIM redundant privileged role assignments where the assigned role appears unused.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh303Free2023-09-14Azure PIM Role Activation Without MFA Alert (noMfaOnRoleActivationAlertIncident)
Alerts when Azure PIM signals role activation occurred without MFA.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh418Free2023-09-14Azure AD PIM Role Activations Too Frequent for Same User
Alerts when Azure PIM logs sequential activation renewals for the same role by the same user.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh151Free2023-09-14Azure PIM Alert: Privileged Role Assigned Outside PIM
Detects Azure PIM risk events indicating privileged role assignments were made outside PIM.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh194Free2023-09-14