Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,262 rules
Windows Registry Event Log Tampering by Disabling WINEVT Channel Enabled Key
Flags registry changes that set WINEVT channel Enabled to 0x00000000 to disable Windows event logging.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh223Free2022-07-04Windows UAC Bypass via IDiagnosticProfileUAC Triggered from DllHost.exe
Flags elevated process creation where DllHost.exe launches using the specific IDiagnosticProfileUAC /Processid value.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh257Free2022-07-03Windows: DllHost.exe creates a System32 DLL for UAC bypass via IDiagnosticProfileUAC
Alerts when dllhost.exe creates a System32 .dll consistent with IDiagnosticProfileUAC UAC bypass behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh343Free2022-07-03Windows: Execution of .xbap via PresentationHost.exe from Uncommon Paths
Alerts when PresentationHost.exe launches a .xbap file from a non-standard location on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium319Free2022-07-01Windows: Execution of ScriptRunner.exe with appvscript Argument
Flags ScriptRunner.exe executions that include the " -appvscript " parameter in the command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2022-07-01Azure Audit Logs: UserType updated from Guest to Member
Alerts when an Azure user’s UserType is updated from Guest to Member, indicating potential privilege elevation.
MikeDuddington, '@dudders1', Huntrule TeamAzureauditlogsMedium439Free2022-06-30Windows: Suspicious LSASS handle access via svchost.exe call trace to seclogon.dll
Flags svchost.exe attempting LSASS access (granted access 0x14c0) with seclogon.dll in the call trace.
Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh264Free2022-06-29Windows: assoc.exe Changes File Extension Handler to exefile
Alerts on cmd.exe running assoc to set file extension handlers to exefile, indicating possible persistence via file associations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-06-28Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Flags bitsadmin.exe file downloads that target suspicious folders using /transfer, /create, and /addfile command-line parameters.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-06-28Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Flags bitsadmin.exe commands that transfer or add files with suspicious extensions based on process creation command-line content.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2022-06-28Windows BITSAdmin Downloads from File-Sharing Domains
Alerts on BITSAdmin downloads from popular file-sharing domains when transfer/create/addfile command-line flags are present.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-06-28Windows Process Creation: bitsadmin Download Using Direct IP URL
Alerts when bitsadmin.exe is used to download via a direct IP address in the command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-06-28Windows attrib.exe sets hidden system file attribute (+s) on suspicious paths and script/executable extensions
Flags attrib.exe usage with +s to mark .exe/.dll and script files in public/temp/user-writable locations as system files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-06-28PowerShell disables or removes ETW Trace via Set-EtwTraceProvider or Remove-EtwTraceProvider
Flags PowerShell commands that remove or disable ETW trace providers to impair Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-06-28Windows BITS Transfer Job Download to Suspicious File Paths
Flags new Windows BITS transfer jobs that save downloaded files into predefined suspicious paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientHigh2810Free2022-06-28