Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,112 rules
IFM Creation Detected from Commandline - Installation from Media (via process_creation)
This rule detects create an IFM image (usually used for deploying domain controllers to reduce replication traffic) for dumping credentials.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-31Suspicious Lateral Movement by Mounting a Network Share - Net Use - Command (via security)
This rule detects move laterally by mounting a network share using compromised user credentials.
HuntRule TeamWindowssecurityMedium30Premium2026-08-31Malicious Impacket DCOMexec Privilege Abuse via MMC (via security)
This rule detects execute the Impacket DCOMexec tool in order to abuse DCOM services.
HuntRule TeamWindowssecurityHigh50Premium2026-08-31Obfuscated Encoded PowerShell Payload Deployed via Process Execution (via process_creation)
This rule detects deployed an encoded PowerShell payload via a process execution. Some parameters are commented in case you would like to reduce false positives or make the rule more precise.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Suspicious Windows Native Pktmon Sniffer Abuse (via process_creation)
This rule detects use the Windows sniffer Pktmon in order to capture sensitive information or credentials.
HuntRule TeamWindowsprocess_creationMedium00Premium2026-08-31OpenSSH Server Listening on Socket (via openssh)
This rule detects enables the OpenSSH server and server starts to listening on SSH socket.
HuntRule TeamWindowsopensshMedium10Premium2026-08-31BITS Payload Downloaded via PowerShell (via powershell)
This rule detects downloads a payload by abusing BITS software. For more precise information, inspect "Bits-client" event log and search for ID 59 and 60.
HuntRule TeamWindowspowershellMedium10Premium2026-08-31Malicious WMI Spwaning PowerShell Process - WMImplant (via process_creation)
This rule detects wMIimplant.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Obfuscated Encoded PowerShell Payload Deployed - PowerShell (via powershell)
This rule detects deployed a service pointing to a hidden and encoded PowerShell payload.
HuntRule TeamWindowspowershellHigh50Premium2026-08-31Malicious Scheduled Task Created and Deleted Fastly - ATexec.py (via security)
This rule detects abuse task scheduler capacities to execute commands or elevate privileges.
HuntRule TeamWindowssecurityHigh30Premium2026-08-31SharpHound Host Enumeration Over Kerberos (via security)
This rule detects detect if a source host is requesting multiple Kerberos Service tickets (TGS) for different assets in a short period of time.
HuntRule TeamWindowssecurityMedium10Premium2026-08-31Malicious Event Log Cleared Using Diagnostics - Via PowerShell (via powershell)
This rule detects clear the event logs.
HuntRule TeamWindowspowershellHigh60Premium2026-08-31DoT (DNS Over TLS) Activation - Command (via process_creation)
This rule detects enable DNS over TLS in order to evade detection for command and control purposes.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-08-31Suspicious System Time Changed (via security)
This rule detects change the system time to evade defense. Check also if NewTime is different from PreviousTime to reduce false positives.
HuntRule TeamWindowssecurityMedium20Premium2026-08-31Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
This rule detects connect to a Windows host using the SSH protocol.
HuntRule TeamWindowssecurityMedium110Premium2026-08-31