Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,116 rules
Malicious Event Log Cleared Using Diagnostics - Via PowerShell (via powershell)
This rule detects clear the event logs.
HuntRule TeamWindowspowershellHigh60Premium2026-08-31DoT (DNS Over TLS) Activation - Command (via process_creation)
This rule detects enable DNS over TLS in order to evade detection for command and control purposes.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-08-31Suspicious System Time Changed (via security)
This rule detects change the system time to evade defense. Check also if NewTime is different from PreviousTime to reduce false positives.
HuntRule TeamWindowssecurityMedium20Premium2026-08-31Suspicious Success Login Attempt on a Windows OpenSSH Server (via security)
This rule detects connect to a Windows host using the SSH protocol.
HuntRule TeamWindowssecurityMedium110Premium2026-08-31SPN Enumeration Previous to Kerberoasting Attack - Native Commands (via process_creation)
This rule detects retrieve SPN using commandline and native tools.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Suspicious Modification of a Sensitive Group Policy - GPO (via security)
This rule detects will attempt to take control over a group policy.
HuntRule TeamWindowssecurityMedium40Premium2026-08-31Malicious Edge Abuse for Payload Download via Console (via process_creation)
This rule detects attemptes to download a payload directly via console.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-31Obfuscated Certutil Payload Obfuscation - Command (via process_creation)
This rule detects abuse certutil command to download obfuscated malicious payload. Tools like Tchopper can trigger this rule.
HuntRule TeamWindowsprocess_creationHigh80Premium2026-08-31Malicious User Account Created by a Computer Account (via security)
This rule detects would abuse some privileges while realying host credentials to escalate privileges.
HuntRule TeamWindowssecurityHigh50Premium2026-08-31Malicious Netsh Helper DLL Abuse - Process (via process_creation)
This rule detects abuses the Netsh DLL feature to perform some code execution.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious WMI Registration - PowerShell (via powershell)
This rule detects createsan instance of a WMI class using tools like WMImplant or PowerLurk.
HuntRule TeamWindowspowershellHigh30Premium2026-08-31Malicious SQL Server Sqlcmd Utility Abuse for Privilege Escalation (via process_creation)
This rule detects uses sqlcmd utility to escalate privileges or introduce weaknesses.
HuntRule TeamWindowsprocess_creationHigh30Premium2026-08-31Malicious User Application Credentials Dump via Network Share - DonPapi, Lazagne (via security)
This rule detects attempt to dump application credentials (Firefox, VNC, Google Chrome, ...) via network share.
HuntRule TeamWindowssecurityHigh30Premium2026-08-31NTFS Hard Link Creation (via process_creation)
This rule detects create a hard link.
HuntRule TeamWindowsprocess_creationMedium30Premium2026-08-31In-Memory Security Package (SSP) Added - Reg via Command (via process_creation)
This rule detects adds a reference in the registry to a malicious SSP (Security Support Provider). Note that this rule will not work with "in memory" SSP injection (Mimikatz).
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31