Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,271 rules
Windows Process Command Line Contains NTFS 8.3 Short Filename Patterns (~1/~2.*)
Detects Windows command lines referencing NTFS 8.3 short names like ~1.exe or ~2.ps1.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium151Free2022-08-05Windows Process Creation: Remove-MpPreference Used to Tamper Windows Defender Settings
Flags process executions that call Remove-MpPreference with Defender tampering-related parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-08-05Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh436Free2022-08-05Windows Suspicious File Creation in AppData Outside Common Subdirectories
Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh82Free2022-08-05Windows Defender Exploit Guard Tamper via Controlled Folder Access AllowedApplications or ProtectedFolders Changes
Alerts on Windefend EventID 5007 when Exploit Guard ProtectedFolders or AllowedApplications lists are modified.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh103Free2022-08-05Azure Audit Logs: Removal of Privileged Role Eligible Members
Flags Azure audit log events indicating bulk removal of eligible members from privileged roles.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh175Free2022-08-05Windows RDP Tunneling Using plink.exe on Local Port 3389
Alert on plink.exe command lines referencing 127.0.0.1:3389 or port 3389, suggesting potential RDP tunneling on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-08-04Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
Florian Roth (Nextron Systems), Microsoft (idea), Huntrule TeamWindowsprocess_creationHigh90Free2022-08-04Windows PsExec Named Pipe Creation from Suspicious Paths (PSEXESVC)
Alerts on PsExec pipe \PSEXESVC creation when the executing image path is in public/temp/desktop/downloads locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdMedium322Free2022-08-04Azure AD: Detect Removal From Group With Conditional Access Policy Modification Rights
Alerts when a user is removed from a group that can modify Conditional Access policies in Azure Entra.
Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner', Huntrule TeamAzureauditlogsMedium101Free2022-08-04Azure Entra: Added member to group granting Conditional Access policy modification
Alerts when a user is added to a group that can modify Conditional Access policies in Azure Entra ID.
Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner', Huntrule TeamAzureauditlogsMedium102Free2022-08-04Windows: Detect wusa.exe Cab Extraction Using /extract
Flags wusa.exe running with /extract:, a behavior consistent with CAB extraction and potential payload staging.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2022-08-04Windows CLI usage of obfuscated IP address patterns in ping/arp commands
Alerts when ping or arp command lines include obfuscated/encoded IP address indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-08-03Windows Process Creation: Obfuscated IP Address in Download Command URLs
Alerts on Windows download commands that include obfuscated/encoded IP addresses in the URL.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-08-03Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical407Free2022-08-03