Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,214 rules
Windows Process Command-Line Flags Indicating Auditpol Policy Tampering
Detects auditpol runs with flags that disable key audit categories, indicating potential audit policy tampering for defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-12-18Windows: java.exe Parent Spawning cmd/powershell/bash Processes
Alerts when java.exe launches cmd, PowerShell, or bash on Windows, a potential sign of command execution.
Andreas Hunkeler (@Karneades), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium70Free2021-12-17Windows: Alert on Java.exe Spawning Suspicious System and Script Binaries
Triggers when java.exe launches a child utility commonly abused for command execution and administration.
Andreas Hunkeler (@Karneades), Florian Roth, Huntrule TeamWindowsprocess_creationHigh70Free2021-12-17Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
frack113, Huntrule TeamWindowsprocess_creationHigh403Free2021-12-16PowerShell Security Software Discovery Using get-process Piped to where-object (Windows)
Flags PowerShell scripts that enumerate processes and filter results for security software by vendor/product keywords.
frack113, Anish Bogati, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium161Free2021-12-16Windows PowerShell: Query SMB Shares via Get-SmbShare
Alerts on PowerShell script blocks running Get-SmbShare to discover SMB shares.
frack113, Huntrule TeamWindowsps_scriptLow103Free2021-12-15PowerShell ScriptBlock Enumeration of AD Group Membership and User Attributes (Windows)
Flags PowerShell script blocks querying AD group membership and user details for discovery of privileged directory information.
frack113, Huntrule TeamWindowsps_scriptLow351Free2021-12-15PowerShell Module: Get-SmbShare Used for SMB Share Discovery
Detects PowerShell module usage of Get-SmbShare to enumerate SMB shares across networked systems.
frack113, Huntrule TeamWindowsps_moduleLow465Free2021-12-15PowerShell module enumeration of AD principals via get-ADPrincipalGroupMembership
Flags PowerShell module usage of Get-ADPrincipalGroupMembership and Get-ADUser with -pr -f patterns indicative of AD discovery.
frack113, Huntrule TeamWindowsps_moduleLow234Free2021-12-15Windows Directory Services: CVE-2021-42287 SAMAccountName spoofing validation failures
Looks for Directory Services SAM validation failures (Event 16990/16991) that may indicate CVE-2021-42287 exploitation attempts.
frack113, Huntrule TeamWindowssystemMedium2810Free2021-12-15Windows Kerberos Key Distribution Center: CVE-2021-42278 Exploitation Attempt Indicators (Event 35–38)
Alerts on Windows Kerberos KDC ticket anomalies (EventIDs 35–38) associated with CVE-2021-42278 exploitation attempts.
frack113, Huntrule TeamWindowssystemMedium412Free2021-12-15Windows process execution of where.exe with browser bookmark database or history artifacts
Alerts on where.exe executions referencing browser history/bookmarks/cookie database artifacts in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow102Free2021-12-13Windows: Delete Backup or System State Backups via wbadmin.exe
Flags wbadmin.exe command lines that delete backup or system state backups, potentially impacting recovery.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium141Free2021-12-13Windows wbadmin.exe Deletes All Backup Copies (keepVersions:0)
Flags wbadmin.exe executions that delete all backups/system state backups using keepVersions:0.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-12-13Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
frack113, Huntrule TeamWindowsprocess_creationHigh245Free2021-12-13