Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,096 rules
BITS Payload Downloaded via Commandline (via process_creation)
This rule detects downloads a payload by abusing BITS software. For more precise information, inspect "Bits-client" event log and search for ID 59 and 60.
HuntRule TeamWindowsprocess_creationMedium40Premium2026-09-02Suspicious Group Discovery - Command (via process_creation)
This rule detects enumerate local or domain groups via commandline.
HuntRule TeamWindowsprocess_creationMedium20Premium2026-09-02Malicious SQL Server Dedicated Admin Connection (DAC) Suspicious Activity (via application)
This rule detects enabled the DAC mode in order to bypass access controls, logon triggers, perform brute force attacks or run unauthorized queries.
HuntRule TeamMssqlapplicationHigh40Premium2026-09-02Malicious Service Deactivation - Command (via process_creation)
This rule detects disable.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-09-02BitLocker Feature Activation on Multiple Hosts - Native (via bitlocker)
This rule detects enable or reconfigure BitLocker on multiple hosts for ransomware purposes.
HuntRule TeamWindowsbitlockerHigh50Premium2026-09-02Malicious Brutforce Enumeration on Windows OpenSSH Server with Non Existing User (via security)
This rule detects sSH brutforce a Windows OpenSSH server with non existing users.
HuntRule TeamWindowssecurityHigh40Premium2026-09-02Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)
This rule detects uses the Tchopper tool by remotely creating multiple services via named pipes.
HuntRule TeamWindowssecurityHigh30Premium2026-09-01Malicious Audit Policy Disabled by Command Line (via process_creation)
This rule detects disbale or clear the audit policy for defense evasion purposes.
HuntRule TeamWindowsprocess_creationHigh10Premium2026-09-01Malicious Shared Folder Access with Forged Golden Ticket (via security)
This rule detects used a forged Golden ticket to login on a remote shared folder. Per default or if specified, the ticket will be forged using the builtin administrator account (SID *-500). However, and it frequent cases, a non suspicious user name will be specificied during the forge in order to evade security monitoring. The rule works based on this trick.
HuntRule TeamWindowssecurityHigh30Premium2026-09-01Malicious User Files Dump via Network Share - DonPapi, Lazagne (via security)
This rule detects attempt to dump user profile information via network share.
HuntRule TeamWindowssecurityHigh40Premium2026-09-01Malicious LSASS Credential Dump with LSASSY - Kernel Access (via security)
This rule detects remotely dump LSASS credentials using the LSASSY tool.
HuntRule TeamWindowssecurityHigh40Premium2026-09-01SystemNightmare by GentilKiwi - External Printer Mapped - CVE-2021-1675 / CVE-2021-34527 (via security)
This rule detects exploit the PrintNightmare vulnerability by abusing the Windows print spooler using the service exposed by Gentilkiwi.
HuntRule TeamWindowssecurityHigh50Premium2026-09-01Obfuscated RDP Tunneling Configuration Enabled for Port Forwarding (via process_creation)
This rule detects configure port forwarding on a host to redirect traffic to a C&C target.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-09-01Malicious Metasploit Reverse Shell Injection in SQL Server (via process_creation)
This rule detects inject a payload into SQL Server in order to obtain a remote shell.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-01Malicious Impacket WMIexec Process Execution (via process_creation)
This rule detects execute WMIexec in order to escalate privileges.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-09-01