Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows: Uncommon Process Access to Chromium User Data Cookies and History
Alerts on uncommon executables reading Chromium cookies/history/web data on Windows, excluding common system and installer paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessLow70Free2024-07-29Windows Remote Thread Creation in cmd.exe or PowerShell.exe
Alert on remote thread creation where cmd.exe or PowerShell.exe is the initiating process, excluding common system and Defender sources.
Splunk Research Team, Huntrule TeamWindowscreate_remote_threadMedium100Free2024-07-29Windows Process Chain Involving Notepad++ Launched via RDPInit and Executed Through CMD
Alerts on rdpinit.exe -> notepad++.exe -> cmd.exe process chain consistent with interactive command execution.
Alex Walston (@4ayymm), Huntrule TeamWindowsprocess_creationMedium345Free2024-07-29Windows Process Creation: net.exe or PowerShell creating AD group "ESX Admins"
Alerts on net.exe or PowerShell attempts to create a domain group named "ESX Admins" via AD/command-line parameters.
frack113, Huntrule TeamWindowsprocess_creationHigh112Free2024-07-29Windows Process Creation Ending in .exe With No Image Name
Flags Windows process creation events where the .exe path exists but the image name is missing, indicating possible stealth or evasion.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium103Free2024-07-23Windows: Detect execution of renamed BOINC.exe binary
Flags renamed BOINC executables on Windows by matching OriginalFileName=BOINC.exe when the executed image name differs.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium468Free2024-07-23PowerShell Launch With --headless From Conhost.exe on Windows
Flags headless ConHost launching PowerShell on Windows based on process name and command-line arguments.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium142Free2024-07-23Windows Child Process Spawned from conhost.exe with --headless
Alerts when conhost.exe launches a child process using the --headless flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2024-07-23Windows Process Execution with 'University of California, Berkeley' Description
Alerts on Windows process creation events whose Description contains "University of California, Berkeley."
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationInformational50Free2024-07-23Windows: Uncommon Process Access to Microsoft Teams Cookies or Local Storage leveldb
Alerts on access to Teams Cookies or leveldb files by processes other than Teams.exe on Windows.
"@SerkinValery, Huntrule Team"Windowsfile_accessMedium81Free2024-07-22Windows File Access Attempt to Panther\unattend.xml During Unattended Install
Alerts on attempts to access Panther\unattend.xml on Windows, a potential source of embedded credentials.
frack113, Huntrule TeamWindowsfile_accessLow90Free2024-07-22Windows COM CLSID Hijacking via Registry Default InprocServer32/LocalServer32 Modification
Detects registry changes to COM CLSID Default InprocServer32/LocalServer32 values that point to suspicious locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh393Free2024-07-16Windows Process Creation: Renamed Microsoft Teams Executable Launch
Alerts when Microsoft Teams binaries are launched under renamed executable names on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium231Free2024-07-12Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Alerts when DsrmAdminLogonBehavior registry value is changed on Windows, except the default DWORD 0x00000000.
Nischal Khadgi, Huntrule TeamWindowsregistry_setHigh422Free2024-07-11Windows Process Execution of BitLockerToGo.EXE
Alerts on Windows execution of BitLockerToGo.exe, a rarely used BitLocker To Go component for portable drive encryption.
Josh Nickels, mttaggart, Huntrule TeamWindowsprocess_creationLow3810Free2024-07-11