Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,340 rules
Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)
Alerts on Windows Security Event 4649 indicating a Kerberos replay error (KRB_AP_ERR_REPEAT).
frack113, Huntrule TeamWindowssecurityHigh429Free2022-10-14Windows Security Event 6423: Device Installation Blocked by Policy
Alerts when Windows blocks a device installation due to enforced system policy (Event ID 6423).
frack113, Huntrule TeamWindowssecurityMedium102Free2022-10-14Windows Security Event Add/Remove Computer Account (4741/4743)
Alerts on Windows domain computer account create/delete activity via Security event 4741 and 4743.
frack113, Huntrule TeamWindowssecurityLow80Free2022-10-14Windows svchost.exe Spawning Office Applications via COM Object Execution
Flags svchost.exe creating new Office app processes (Word/Excel/PowerPoint/etc.), consistent with Office COM automation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2022-10-13Windows: ssh.exe RDP tunneling to :3389 via SSH
Alerts on Windows process executions of ssh.exe that reference RDP port :3389 for SSH tunneling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-10-12Port Forwarding via SSH.EXE on Windows
Flags Windows executions of ssh.exe using remote port forwarding (-R) based on process creation command-line content.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3110Free2022-10-12Windows Credential Manager Vault/File Access by Uncommon Application Images
Alerts on access to Windows credential/vault files by uncommon processes based on image path and file location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_accessMedium111Free2022-10-11Windows Process Hacker Execution Identified by Image Metadata and Hashes
Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium92Free2022-10-10Windows PowerShell Recon Using Get-LocalGroupMember on Local/Well-Known Groups
Flags PowerShell Get-LocalGroupMember usage targeting notable local group names in process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium175Free2022-10-10Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh113Free2022-10-10Windows MSSQL: Extended Stored Procedure execution with provider name MSSQLSERVER and message containing 'maggie'
Flags MSSQLSERVER extended stored procedure events where the message contains 'maggie', indicating potential backdoor usage.
Denis Szadkowski, DIRT / DCSO CyTec, Huntrule TeamWindowsapplicationHigh238Free2022-10-09Windows: NPS (npc.exe) Port Forwarding Proxy Execution via Command-Line Parameters
Flags Windows executions of npc.exe with NPS server, vkey/password, or config=npc command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh455Free2022-10-08Windows Execution of IOX (iex/port forwarding) Tunnel/Proxy Tool via Process Creation
Alerts on Windows process creation for iox.exe with tunneling/proxy forwarding command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2022-10-08Windows Process Creation: SharpWSUS or WSUSpendu Execution via PowerShell Parameters
Detects command-line execution patterns for SharpWSUS or WSUSpendu on Windows.
"@Kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh246Free2022-10-07Windows LPE Attempt via TabTip CLSID Using Microsoft-Windows-DistributedCOM (Event ID 10001)
Alerts when TabTip.exe is started via CLSID/DCOM activation in Windows DistributedCOM EventID 10001.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh61Free2022-10-07