Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,347 rules
Windows Service Installation: TacticalRMM Agent Service (SCM Event 7045)
Flags Windows service installations that include tacticalrmm.exe and the TacticalRMM Agent Service using SCM Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium91Free2022-11-28Windows Service Control Manager: Mesh Agent Service Installation via Service Creation (7045)
Flags Windows Event ID 7045 service installations that reference MeshAgent.exe or “Mesh Agent”.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium342Free2022-11-28Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.
Janantha Marasinghe, Huntrule TeamAzuresigninlogsHigh81Free2022-11-27Windows UAC Bypass via Event Viewer RecentViews Path in Process Command Line
Flags Windows processes whose command lines reference Event Viewer RecentViews and use redirection, consistent with UAC bypass techniques.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2022-11-22Windows Registry NGenAssemblyUsageLog Key Tampering via .NET Usage Log Configuration
Alerts on registry modifications to the .NETFramework NGenAssemblyUsageLog key that can disrupt .NET Usage Log creation.
frack113, Huntrule TeamWindowsregistry_setHigh176Free2022-11-18Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Flags secedit.exe command lines used to export or configure Windows security policy.
Janantha Marasinghe, Huntrule TeamWindowsprocess_creationMedium133Free2022-11-18Windows: Suspicious Powercfg Execution Changing Lock/Video Standby Timeout
Detects powercfg.exe commands attempting to change standby/lock-related timeouts on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium82Free2022-11-18Windows: Suspicious Msbuild.exe execution from uncommon parent process
Alerts when Msbuild.exe runs under an unexpected parent process on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2022-11-17PowerShell Get-ADUser User Discovery and Data Export via File Output
Detects PowerShell Get-ADUser-based user enumeration combined with exporting results to files or output streams.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium91Free2022-11-17PowerShell Get-ADComputer Cmdlet Used for Computer Discovery and File Export
Flags PowerShell Get-ADComputer wildcard enumeration followed by writing exported computer data to a file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium80Free2022-11-17Microsoft 365 Threat Management: PST Export via New-ComplianceSearchAction -Export
Flags M365 SecurityComplianceCenter activity that includes New-ComplianceSearchAction with -Export for PST content.
Nikita Khalimonenkov, Huntrule TeamM365threat_managementMedium163Free2022-11-17Windows file activity matching CrackMapExec/Impacket-secretsdump credential dumping temp output patterns
Alerts on Windows temp file creations consistent with CrackMapExec or Impacket-secretsdump credential dumping activity.
SecurityAura, Huntrule TeamWindowsfile_eventHigh3010Free2022-11-16Windows Driver Load: Process Hacker (processhacker.sys) Presence
Flags Windows driver loads of Process Hacker’s processhacker.sys using path and known imphash indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh143Free2022-11-16Windows Process Creation: Suspicious RunAs-Like Command-Line Flag Combination
Flags Windows processes with both target-user and target-command flags in the same command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium91Free2022-11-11PowerShell Get-ADComputer Export of Active Directory Computer Data to File (Windows)
Detects PowerShell running Get-ADComputer (* filter) and exporting results to a file via output/content cmdlets.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-11-10