Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,252 rules
Windows Service ImagePath Set to Non-Admin Controlled Directory
Alerts when a Windows service’s ImagePath is changed to a binary path under AppData or ProgramData.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setMedium60Free2022-05-02Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)
Flags process executions of gpresult.exe that request RSoP details using /z and /v on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium476Free2022-05-01Windows svchost.exe RDP (3389) Connections to HTTP/HTTPS Ports 80 or 443
Alerts when svchost.exe initiates from TCP 3389 to destination ports 80 or 443, consistent with possible RDP tunneling over web ports.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh162Free2022-04-29Windows: Detect ngrok Traffic Forwarded to Local RDP Port via TerminalServices Logs
Detects suspicious ngrok usage that forwards to the local RDP port using Windows TerminalServices-LocalSessionManager EventID 21.
Florian Roth (Nextron Systems), Huntrule TeamWindowsterminalservices-localsessionmanagerHigh111Free2022-04-29Windows rundll32.exe executing InstallScreenSaver via desk.cpl SCR File
Detects rundll32.exe launches with InstallScreenSaver behavior via desk.cpl, a screensaver execution technique.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, TactiKoolSec, Huntrule TeamWindowsprocess_creationMedium194Free2022-04-28Windows Microsoft Sync Center (mobsync.exe) Network Connections to Public IPs
Alerts when mobsync.exe makes outbound connections to destination IPs outside private/local ranges.
elhoim, Huntrule TeamWindowsnetwork_connectionMedium327Free2022-04-28Windows: Copying Executable or DLL Files into Default GPO Policies Folder
Alerts when .exe/.dll files are created in the default GPO storage folder path.
elhoim, Huntrule TeamWindowsfile_eventMedium4010Free2022-04-28Windows: Files created by Microsoft Sync Center (mobsync.exe) with .dll/.exe extensions
Flags .dll and .exe files created by mobsync.exe on Windows.
elhoim, Huntrule TeamWindowsfile_eventMedium264Free2022-04-28Windows: rundll32.exe spawning explorer.exe child process (shell32.Control_RunDLL)
Alerts on rundll32.exe spawning explorer.exe, an uncommon child process pattern that may indicate stealthy execution via shell components.
elhoim, CD_ROM_, Huntrule TeamWindowsprocess_creationHigh142Free2022-04-27Windows Process Creation: KrbRelay.exe Kerberos Relay Tool Execution
Flags Windows process creation for KrbRelay.exe with Kerberos relaying-related command-line arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-04-27Windows Hacktool Execution via PE Metadata Company Field
Flags execution of Windows binaries with PE Company metadata set to "Cube0x0", even when renamed.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-04-27Windows UAC Bypass via Event Viewer RecentViews File Creation
Alerts on suspicious file events to Event Viewer RecentViews paths that may indicate a Windows UAC bypass attempt.
Antonio Cocomazzi (idea), Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh269Free2022-04-27Windows: Detect .SCR screen saver file creation outside common system directories
Alerts on creation of .scr screen saver files in unusual locations on Windows.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamWindowsfile_eventMedium277Free2022-04-27Windows Successful Local Kerberos Logon to Built-in Administrator (Possible Privilege Escalation)
Alert on successful local (127.0.0.1) Kerberos logons targeting the built-in Administrator SID for potential privilege escalation.
Elastic, @SBousseaden, Huntrule TeamWindowssecurityHigh102Free2022-04-27Windows: Detect KrbRelayUp.exe HackTool Process Execution
Flags Windows process executions of KrbRelayUp.exe with relay/domain and SCM spawn command-line patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh359Free2022-04-26