Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,224 rules
Windows PowerShell ScriptBlock checks for service registry ACL inspection
Flags PowerShell scripts that use Get-ACL to inspect service Registry keys under HKLM\SYSTEM\CurrentControlSet\Services.
frack113, Huntrule TeamWindowsps_scriptMedium161Free2021-12-30Windows PowerShell script sets COR_PROFILER environment variables for .NET CLR profiling
Alerts on PowerShell script blocks that set CLR profiler environment variables (COR_ENABLE_PROFILING/COR_PROFILER/COR_PROFILER_PATH).
frack113, Huntrule TeamWindowsps_scriptMedium152Free2021-12-30Windows: File creation of C:\program.exe enabling unquoted service path execution
Flags creation of C:\program.exe that can be used to hijack unquoted Windows service binary paths.
frack113, Huntrule TeamWindowsfile_eventHigh388Free2021-12-30Windows: Suspicious .SCR Screensaver File Creation
Alerts on creation of new .scr screensaver binaries on Windows, excluding known benign paths and a specific TiWorker case.
frack113, Huntrule TeamWindowsfile_eventMedium82Free2021-12-29Windows File Creation: Custom Application Shim Database Files Created
Flags creation of custom Application Shim database files in AppPatch custom directories on Windows.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium453Free2021-12-29Windows Registry Changes to Outlook Security Settings
Alerts on registry updates to Outlook security configuration keys on Windows, excluding direct Outlook.exe changes.
frack113, Huntrule TeamWindowsregistry_setMedium122Free2021-12-28Windows Registry Startup: Chrome VPN Extensions Installed via Extension Registry Keys
Flags Windows Registry updates that register VPN/proxy Chrome extensions via the Chrome Extensions update_url key.
frack113, Huntrule TeamWindowsregistry_setHigh91Free2021-12-28Windows Process Creation: Suspicious Kernel Dump via dtrace.exe lkd(0) and syscall:::return
Alerts on Windows process executions of dtrace.exe with command lines consistent with kernel dumping (lkd).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh336Free2021-12-28PowerShell ScriptBlock Requests Kerberos Tickets via IdentityModel Token Assembly
Alerts on PowerShell ScriptBlock text that builds Kerberos ticket requests using KerberosRequestorSecurityToken and .GetRequest().
frack113, Huntrule TeamWindowsps_scriptHigh132Free2021-12-28PowerShell Script Blocks Register Malicious XLL via Office COM Automation on Windows
Detects PowerShell Script Block content that uses COM automation to call .RegisterXLL for an Office XLL add-in.
frack113, Huntrule TeamWindowsps_scriptHigh414Free2021-12-28Windows PowerShell Local User Account Manipulation via Script Block Logging
Alerts when PowerShell script blocks invoke local user management cmdlets that can be used to maintain persistence.
frack113, Huntrule TeamWindowsps_scriptMedium299Free2021-12-28PowerShell AD Account Creation Library Usage via AccountManagement Namespace on Windows
Alert on PowerShell Script Block content referencing System.DirectoryServices.AccountManagement, indicating potential AD principal manipulation.
frack113, Huntrule TeamWindowsps_scriptMedium311Free2021-12-28PowerShell Scheduled Task Creation via ScriptBlock Logging
Identifies PowerShell script blocks that create and register scheduled tasks using TaskScheduler cmdlets or CIM WMI method calls.
frack113, Huntrule TeamWindowsps_scriptMedium92Free2021-12-28Windows PowerShell Screen Capture via CopyFromScreen
Flags PowerShell scripts containing .CopyFromScreen, indicative of desktop screen capture activity.
frack113, Huntrule TeamWindowsps_scriptMedium101Free2021-12-28Windows Suspicious File Downloads from Outlook/OneNote Attachment Domains via Command-Line
Flags Windows command-line downloads using curl/wget or PowerShell from Outlook/OneNote attachment domains.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2021-12-27