Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,262 rules
Windows: msdt.exe Loads sdiageng.dll via Image Load Events
Flags msdt.exe image-load events that load sdiageng.dll, a behavior commonly associated with DLL side-loading abuse.
Greg (rule), Huntrule TeamWindowsimage_loadHigh169Free2022-06-17Azure AD Sign-ins Using Legacy Authentication Client Applications
Alerts on Azure sign-ins using legacy protocol client apps (IMAP/POP3/SMTP/EWS/ActiveSync), which may indicate risky authentication usage.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsHigh152Free2022-06-17Azure AD Account Disabled or Blocked Login Attempt Failures (Sign-in Logs)
Alerts when Azure sign-in attempts fail because the target account is disabled or blocked.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsMedium425Free2022-06-17Windows Process Creation: Sysinternals PsService (PsService*.exe) Execution
Alerts on execution of Sysinternals PsService (PsService*.exe) on Windows, which can support service discovery and tampering.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium4010Free2022-06-16Windows OpenConsole LOLBIN Execution via Process Creation
Alerts when OpenConsole.exe runs (outside a specific Windows Terminal path), potentially used to bypass application whitelisting.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium319Free2022-06-16Windows: FakeUpdates/SocGholish execution via wscript loading a zip-based update script
Flags wscript launched from Temp update .js within a .zip to spawn cmd.exe or PowerShell on Windows.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh141Free2022-06-16Windows Registry: Enable ScriptedDiagnostics TurnOffCheck DWORD via Policies
Flags registry policy enabling ScriptedDiagnostics TurnOffCheck (DWORD 0x00000001) on Windows.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamWindowsregistry_setMedium133Free2022-06-15Windows: Execution of Pcalua.exe with -a Argument
Flags Pcalua.exe executions containing " -a" that may indicate indirect command execution on Windows.
Nasreddine Bencherchali (Nextron Systems), E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationMedium392Free2022-06-14Windows forfiles.exe Execution with /c Flag Command Proxying
Flags forfiles.exe executions that include the /c flag, indicating potential indirect command execution.
Tim Rauch, Elastic, E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationMedium121Free2022-06-14Windows conhost.exe Path Traversal in Process Command Line
Detects Windows conhost.exe command lines containing '/../../' path traversal indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-06-14Web Server GET Requests Containing SSTI Payload Strings (Server-Side Template Injection)
Flags GET requests containing SSTI probe strings in web access logs when the response is not 404.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh172Free2022-06-14Windows msdt.exe execution using PCWDiagnostic.xml answer file
Alerts on msdt.exe launched with PCWDiagnostic.xml and an answer-file argument, excluding cases from pcwrun.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2910Free2022-06-13Windows: Indirect execution of pcwrun.exe using path traversal-style command line content
Detects pcwrun.exe spawning with '../' in the command line, indicating potential indirect execution abuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-06-13Windows Registry Custom File Open Handler Executes PowerShell
Alerts when a registry shell open handler is created to run PowerShell with -command.
CD_R0M_, Huntrule TeamWindowsregistry_setHigh112Free2022-06-11Windows Process: Notepad++ GUP (GUP.exe) Download Execution via -unzipTo and URL
Detects Notepad++ GUP.exe downloading over HTTP initiated by a non-Notepad++ parent process.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh256Free2022-06-10