Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,262 rules
Windows BITS Client Downloads From File-Sharing Domains
Alerts on Windows BITS transfers (EventID 16403) that download from known file-sharing/content hosting domains.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientHigh122Free2022-06-28Azure AD Sign-ins from Unknown Devices with Single-Factor Authentication
Alerts on successful Azure sign-ins using single-factor authentication with unknown or missing device identifiers from non-trusted contexts.
Michael Epping, '@mepples21', Huntrule TeamAzuresigninlogsLow334Free2022-06-28Azure AD Sign-ins from Non-Compliant Devices
Alert on Entra ID sign-ins originating from devices flagged as non-compliant.
Michael Epping, '@mepples21', Huntrule TeamAzuresigninlogsHigh211Free2022-06-28Azure Sign-In Logs: Device Registration or Join Success Without MFA
Flags successful device registration/join attempts in Azure when MFA was not performed per Conditional Access.
Michael Epping, '@mepples21', Huntrule TeamAzuresigninlogsMedium162Free2022-06-28Azure Audit Logs: User Added to Global or Device Administrator Roles
Alerts when Azure AD role-management events add users to Global or Device Administrator roles.
Michael Epping, '@mepples21', Huntrule TeamAzureauditlogsHigh315Free2022-06-28Azure AD/Entra Audit Logs: Device Registration Policy Changes
Alerts on Azure audit log events that set or modify the device registration policy.
Michael Epping, '@mepples21', Huntrule TeamAzureauditlogsHigh459Free2022-06-28Azure Audit Logs: BitLocker Key Read Activity
Alerts on Azure audit events reading BitLocker keys, which can enable recovery and encryption bypass.
Michael Epping, '@mepples21', Huntrule TeamAzureauditlogsMedium101Free2022-06-28Windows dllhost.exe Launched With No Command-Line Arguments
Alerts on dllhost.exe being executed with no command-line arguments, a rare pattern that may indicate stealthy or injected activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-06-27Windows HandleKatz: Duplicate LSASS Handle via Process Access with Handle Duplication Rights
Flags HandleKatz-style behavior duplicating an existing LSASS handle using PROCESS_DUP_HANDLE and ntdll.dll call trace.
Bhabesh Raj (rule), @thefLinkk, Huntrule TeamWindowsprocess_accessHigh245Free2022-06-27Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-06-27Windows: Potential Process Injection via Msra.exe Spawning Suspicious Child Processes
Flags Msra.exe spawning suspicious tools that may indicate process injection or post-exploitation activity on Windows.
Alexander McDonald, Huntrule TeamWindowsprocess_creationHigh162Free2022-06-24Windows DNS Queries Containing ufile.io Domain
Alerts on Windows DNS lookups where the queried name contains ufile.io, indicating potential exfiltration-related activity.
yatinwad, TheDFIRReport, Huntrule TeamWindowsdns_queryLow90Free2022-06-23Windows Process Execution: msdt.exe Launched with -cab Flag
Alerts when msdt.exe is started with the "-cab" argument, consistent with suspicious cabinet-based diagcab usage.
Nasreddine Bencherchali (Nextron Systems), GossiTheDog, frack113, Huntrule TeamWindowsprocess_creationMedium121Free2022-06-21Windows PowerShell: Execution of TroubleshootingPack Cmdlets (msdt-related usage)
Flags PowerShell script blocks invoking TroubleshootingPack with unattended answer-file arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium143Free2022-06-21Windows PowerShell Hotfix Enumeration via Win32_QuickFixEngineering
Detects PowerShell scripts enumerating installed hotfixes by querying Win32_QuickFixEngineering for HotFixID.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium211Free2022-06-21