Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,237 rules
Windows reg.exe Used to Modify RDP Terminal Server Registry Values
Flags reg.exe command lines that modify Terminal Server registry values controlling RDP enablement and behavior.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh2710Free2022-02-12PowerShell DirectorySearcher AD Computer Enumeration via System.DirectoryServices.DirectorySearcher
Flags PowerShell DirectorySearcher queries that load directory properties and enumerate results from Active Directory.
frack113, Huntrule TeamWindowsps_scriptMedium151Free2022-02-12Windows Process Execution: ZeroLogon PoC Tool (cool.exe/zero.exe) via cmd.exe
Alerts on cmd.exe launching cool.exe/zero.exe with ZeroLogon PoC-style arguments and follow-on taskkill or PowerShell activity.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh193Free2022-02-12Windows process creation: flag suspicious program names and PowerShell script indicators
Alerts on suspicious Windows process image names and PowerShell command-line script/tool patterns commonly used in malicious tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-02-11Windows LogMeIn LMIGuardianSvc Execution Associated with Remote Access Tools
Flags Windows process launches identified as LogMeIn LMIGuardianSvc by Description/Product/Company attributes.
frack113, Huntrule TeamWindowsprocess_creationMedium345Free2022-02-11AnyDesk Executable Execution on Windows
Detects AnyDesk-related process launches on Windows by matching executable names and AnyDesk product metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium70Free2022-02-11Windows File Creation Indicators for Local SAM Database Exports
Alerts on Windows file creations with filenames indicative of a local SAM export or backup artifact.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh198Free2022-02-11Windows Recent Files Shortcut Points to ISO/IMG/VHD Mount Images
Flags Windows Recent Items entries that reference ISO/IMG/VHD/VHDX mount shortcuts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventMedium143Free2022-02-11Windows File Events: AnyDesk user.conf and system.conf Temporary Artefacts
Identifies Windows file writes of AnyDesk user.conf or system.conf in AppData\Roaming.
frack113, Huntrule TeamWindowsfile_eventMedium101Free2022-02-11Linux Process Execution of bpftrace with the --unsafe Option
Alerts when bpftrace is executed with the --unsafe option on Linux.
Andreas Hunkeler (@Karneades), Huntrule TeamLinuxprocess_creationMedium124Free2022-02-11Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Alerts on command lines using TrolleyExpress.exe PID parameters consistent with LSASS memory dumping on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-02-10Windows LSASS memory access from TrolleyExpress/ProcessDump/dump64 processes
Alerts on Windows processes attempting to access lsass.exe from TrolleyExpress.exe, ProcessDump.exe, or dump64.exe with dump-like access rights.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh141Free2022-02-10Windows LSASS Memory Access Triggered by Source Image Containing 'dump' Keyword
Alerts when a process named with 'dump' requests specific access rights to lsass.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh70Free2022-02-10Windows Script Interpreter Execution From Suspicious Folders via Command-Line Flags
Flags-and-location-based detection of cscript/wscript/mshta-style script execution launched from TEMP/Public/user directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh338Free2022-02-08Microsoft 365 eDiscovery PST Export or Search Started Success Alert
Alerts on successful eDiscovery search/export activity that produces PST files in Microsoft 365.
Sorina Ionescu, Huntrule TeamM365threat_managementMedium336Free2022-02-08