Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,244 rules
Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Flags web server processes spawning child commands consistent with credential dumping, exfiltration, and privilege changes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-03-17Windows PktMon.exe Process Execution (pktmon.exe / PktMon.exe)
Alerts on Windows executions of PktMon.exe based on process creation image name and OriginalFileName.
frack113, Huntrule TeamWindowsprocess_creationMedium162Free2022-03-17Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
frack113, Huntrule TeamWindowsps_scriptLow133Free2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
frack113, Huntrule TeamWindowsps_scriptLow404Free2022-03-17Windows PowerShell Directory Enumeration via Get-ChildItem and Output Redirection
Flags PowerShell directory enumeration patterns using Get-ChildItem, error suppression, and appended output to a file.
frack113, Huntrule TeamWindowsps_scriptMedium215Free2022-03-17Windows PowerShell Active Directory Group Enumeration via Get-AdGroup Cmdlet
Flags PowerShell script blocks that call Get-ADGroup with -Filter to enumerate Active Directory groups.
frack113, Huntrule TeamWindowsps_scriptLow163Free2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
frack113, Huntrule TeamWindowsps_scriptLow357Free2022-03-17PowerShell Get-ADUser Enumeration Using UserAccountControl DONT_REQ_PREAUTH Flag
Flags Get-ADUser PowerShell scripts enumerating accounts by UserAccountControl DONT_REQ_PREAUTH (4194304).
frack113, Huntrule TeamWindowsps_scriptMedium131Free2022-03-17Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh133Free2022-03-16Windows Remote Thread Creation Targeting Uncommon System Image Processes
Alert on Windows remote thread creation events targeting a predefined list of uncommon processes by image path.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_remote_threadMedium141Free2022-03-16Windows schtasks.exe Create Executes File from AppData\Local
Alerts on schtasks.exe creating tasks that run payloads from C:\Users\<user>\AppData\Local.
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh196Free2022-03-15Linux Process Creation: Shell Command Piped Into Another Shell
Flags Linux processes that start with sh/bash -c and pipe execution into a subsequent shell.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium395Free2022-03-14Linux Process Creation: Interactive Bash With Suspicious Command-Line and Child Image
Flags interactive bash (bash -i) spawning likely malicious children with encoded execution or recon/utility tool invocations.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium132Free2022-03-14Windows Process Creation: Suspicious for/foreach Scan Loop with nslookup or ping
Alerts on Windows command lines using for/foreach loops that also run nslookup or ping, consistent with host scanning.
frack113, Huntrule TeamWindowsprocess_creationMedium113Free2022-03-12Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh215Free2022-03-12