Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
SPN Enumeration Previous to Kerberoasting Attack - Native Commands (via process_creation)
This rule detects retrieve SPN using commandline and native tools.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Edge Abuse for Payload Download via Console (via process_creation)
This rule detects attemptes to download a payload directly via console.
HuntRule TeamWindowsprocess_creationHigh50Premium2026-08-31Obfuscated Certutil Payload Obfuscation - Command (via process_creation)
This rule detects abuse certutil command to download obfuscated malicious payload. Tools like Tchopper can trigger this rule.
HuntRule TeamWindowsprocess_creationHigh110Premium2026-08-31Malicious User Account Created by a Computer Account (via security)
This rule detects would abuse some privileges while realying host credentials to escalate privileges.
HuntRule TeamWindowssecurityHigh60Premium2026-08-31Malicious Netsh Helper DLL Abuse - Process (via process_creation)
This rule detects abuses the Netsh DLL feature to perform some code execution.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious WMI Registration - PowerShell (via powershell)
This rule detects createsan instance of a WMI class using tools like WMImplant or PowerLurk.
HuntRule TeamWindowspowershellHigh50Premium2026-08-31Malicious SQL Server Sqlcmd Utility Abuse for Privilege Escalation (via process_creation)
This rule detects uses sqlcmd utility to escalate privileges or introduce weaknesses.
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Malicious User Application Credentials Dump via Network Share - DonPapi, Lazagne (via security)
This rule detects attempt to dump application credentials (Firefox, VNC, Google Chrome, ...) via network share.
HuntRule TeamWindowssecurityHigh40Premium2026-08-31In-Memory Security Package (SSP) Added - Reg via Command (via process_creation)
This rule detects adds a reference in the registry to a malicious SSP (Security Support Provider). Note that this rule will not work with "in memory" SSP injection (Mimikatz).
HuntRule TeamWindowsprocess_creationHigh40Premium2026-08-31Malicious Microsoft Defender Critical Security Components Disabled - PowerShell (via powershell)
This rule detects disable Defender security features in PowerShell.
HuntRule TeamWindowspowershellHigh80Premium2026-08-31Malicious Rubeus Kerberos Constrained Delegation Abuse - S4U2Proxy (via security)
This rule detects abuse Kerberos constrained delegation in order to escalate privileges.
HuntRule TeamWindowssecurityHigh50Premium2026-08-31Renamed Procdump Tool Used for Dumping LSASS Process (via process_creation)
This rule detects dump the LSASS process content using a renamed version of the Procdump tool.
HuntRule TeamWindowsprocess_creationHigh60Premium2026-08-31Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
This rule detects register the SMBexec service to estasblish persistence.
HuntRule TeamWindowsregistry_eventHigh00Premium2026-08-31Malicious User Creation via Commandline (via process_creation)
This rule detects create a user via commandline.
HuntRule TeamWindowsprocess_creationHigh20Premium2026-08-31Malicious Network Share Discovery And/or Connection via Commandline (via process_creation)
This rule detects enumerate or to establish a connection to a network share.
HuntRule TeamWindowsprocess_creationHigh70Premium2026-08-31