Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,224 rules
Windows Process Execution of Hashcat.exe for Password Cracking
Alerts on Hashcat.exe launched with cracking-focused flags targeting an offline SAM-derived dataset.
frack113, Huntrule TeamWindowsprocess_creationHigh409Free2021-12-27Windows: Findstr searches GPP cpassword in SYSVOL XML
Alerts when Windows findstr/find searches SYSVOL XML files for GPP cpassword.
frack113, Huntrule TeamWindowsprocess_creationHigh417Free2021-12-27Windows PowerShell Credential Guessing via LDAP using System.Net.NetworkCredential
Detects PowerShell scripts referencing LDAP connection and .NET network credential handling, potentially indicating remote credential access activity.
frack113, Huntrule TeamWindowsps_scriptLow141Free2021-12-27Windows PowerShell Copies a DLL into System32 or SysWOW64
Flags PowerShell Copy-Item targeting Windows\System32 or Windows\SysWOW64 for file placement.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2021-12-27Windows schtasks.exe /disable Used to Disable Security-Critical Scheduled Tasks
Flags schtasks.exe executions using /disable against security-critical Windows scheduled task paths.
frack113, Nasreddine Bencherchali (Nextron Systems), X__Junior, Huntrule TeamWindowsprocess_creationHigh71Free2021-12-26Windows: cipher.exe Overwrites Deleted Data Using /w
Flags Windows cipher.exe runs with /w: to overwrite deleted data on disk.
frack113, Huntrule TeamWindowsprocess_creationMedium345Free2021-12-26Windows PowerShell Wallpaper Replacement via Registry and SystemParametersInfo
Identifies PowerShell script blocks that modify the HKCU Desktop\WallPaper setting to replace a user’s wallpaper.
frack113, Huntrule TeamWindowsps_scriptLow302Free2021-12-26Windows PowerShell Script: Remove Account From Domain Admin Group via Remove-ADGroupMember
Alerts on PowerShell commands removing specified members via Remove-ADGroupMember, potentially disrupting Domain Admin access.
frack113, Huntrule TeamWindowsps_scriptMedium121Free2021-12-26Windows Process Termination via taskkill.exe Execution
Alerts on taskkill.exe executions that use /f along with /im or /pid to force-terminate targeted processes.
frack113, MalGamy (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationLow70Free2021-12-26Windows: .txt Created on User Desktop via cmd.exe
Flags cmd.exe creating .txt files under user Desktop, a common ransomware-style artifact placement pattern.
frack113, Huntrule TeamWindowsfile_eventMedium100Free2021-12-26Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh70Free2021-12-22Windows: Detect Computer Account Rename to Non-Standard Name Missing Trailing '$'
Alerts on Windows 4781 computer account renames where the new name lacks the '$' suffix.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh82Free2021-12-22Proxy requests with URI ending in .class extension
Flags proxy requests whose URI path ends with .class, useful for identifying potential Java class downloads.
Andreas Hunkeler (@Karneades), Huntrule Team—proxyMedium60Free2021-12-21Windows Process Creation: Detect Sysinternals Tool Name Impersonation by Executable
Alerts on Windows process executions using filenames that match common Sysinternals tools to indicate potential binary impersonation.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2021-12-20Suspicious Windows Process Creation as SYSTEM User with Likely Credential/Defense Evasion Commands
Flags SYSTEM-context process executions on Windows that include suspicious tool names or command-line patterns such as PowerShell/Mimikatz indicators.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindowsprocess_creationHigh122Free2021-12-20