Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,280 rules
Windows PowerShell Command History Disable via Remove-Module psreadline
Detects PowerShell scripts that remove psreadline with Remove-Module to suppress command history evidence.
Ali Alwashali, Huntrule TeamWindowsps_scriptHigh327Free2022-08-21Windows Script Dropped by Signed Applications and LOLBINs
Detects Windows legitimate/signed executables dropping script files (.ps1, .vbs, .js, etc.) to disk, indicating potential script-based abuse.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh133Free2022-08-21Windows Suspicious App and LOLBIN Dropping Executable Files to Disk
Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh191Free2022-08-21Windows Executable Dropping Archive Files via Common LOLBINs and Office Apps
Alerts when Office or other specified Windows binaries create archive files like .zip/.rar/.7z/.diagcab/.appx on disk.
frack113, Florian Roth, Huntrule TeamWindowsfile_eventHigh237Free2022-08-21Windows Registry COM Hijacking via scrobj.dll InprocServer32(Default) Persistence
Alerts on registry modifications setting InprocServer32(Default) to scrobj.dll, indicating possible COM hijacking persistence.
frack113, Huntrule TeamWindowsregistry_setMedium123Free2022-08-20Windows Process Creation: WebBrowserPassView.exe Execution
Flags Windows execution of WebBrowserPassView.exe, a browser password recovery tool often used for credential access.
frack113, Huntrule TeamWindowsprocess_creationMedium251Free2022-08-20Windows: Code execution via Pester.bat invoked by PowerShell (Invoke-Pester/Get-Help)
Alerts when PowerShell spawns Pester.bat with parent command lines referencing Pester invocation or help usage.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium113Free2022-08-20Windows Process Creation: TruffleSnout.exe Execution
Detects execution of TruffleSnout.exe on Windows using process creation metadata.
frack113, Huntrule TeamWindowsprocess_creationHigh141Free2022-08-20Windows: SharpUp (SharpUp.exe) Local Privilege Escalation Tool Execution
Flags SharpUp.exe execution on Windows when command line indicators reference common privilege-escalation targets.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical203Free2022-08-20Windows: DirLister.exe Execution for Directory Listing Discovery
Alerts on execution of DirLister.exe on Windows, indicating potential directory/file discovery activity.
frack113, Huntrule TeamWindowsprocess_creationLow155Free2022-08-20Windows DNS Query for _ldap.* Using LDAP-Related Discovery
Alerts on _ldap.* DNS queries from uncommon Windows processes, indicating potential LDAP/DNS service discovery.
frack113, Huntrule TeamWindowsdns_queryLow141Free2022-08-20Windows Registry Modification: Suppress Windows Security Center Notifications
Flags setting Notification_Suppress DWORD to 1 in Windows Defender UX policy to disable security center notifications.
frack113, Huntrule TeamWindowsregistry_setMedium337Free2022-08-19Windows Registry: Set DisallowRun DWORD to 0x1 to Block User Program Execution
Detects Windows registry writes setting Explorer\DisallowRun to DWORD 0x1, a defense-impairment behavior.
frack113, Huntrule TeamWindowsregistry_setMedium126Free2022-08-19Windows Registry: Disable Firewall via EnableFirewall DWORD Policies
Flags registry policy changes that set Windows Firewall EnableFirewall to 0 for Domain or Standard profiles.
frack113, Huntrule TeamWindowsregistry_setMedium235Free2022-08-19Windows Registry: Disable Windows Security Center notifications via UseActionCenterExperience
Alerts on registry updates that set UseActionCenterExperience=0 to disable Windows Security Center notifications.
frack113, Huntrule TeamWindowsregistry_setMedium197Free2022-08-19