Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,211 rules
Windows Process Creation: Suspicious Network Configuration and Discovery Commands
Alerts on Windows command-line usage of network configuration and discovery tools (ipconfig, netsh, arp, nbtstat, net config, route print).
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow193Free2021-12-07Windows netsh.exe Firewall Configuration Discovery (show firewall rule/state/name=all)
Flags netsh.exe commands used to enumerate Windows firewall rules and states via “show firewall … name=all”.
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow176Free2021-12-07Windows PowerShell Process Creation with DInjector Cradle Flags (/am51 and /password)
Identifies Dinject PowerShell cradle usage by matching command-line flags '/am51' and '/password' in Windows process creation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical4710Free2021-12-07Windows: Suspicious PowerShell Interactive History Files Created as SYSTEM
Alerts on creation of PowerShell interactive history/profile files under SYSTEM, signaling privileged PowerShell activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh114Free2021-12-07Windows: User Added to Local Remote Desktop Users Group via Net or PowerShell
Detects Windows command-line activity that adds a user to the local Remote Desktop Users group using net localgroup or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh302Free2021-12-06Windows: Network connections initiated to api.mega.co.nz or mega.nz
Identifies initiated Windows outbound connections to api.mega.co.nz/mega.nz for potential file-transfer staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionLow197Free2021-12-06Windows: Remote Network Share Writes to desktop.ini
Flags remote network-shared desktop.ini being written to with high-impact permissions in Windows Security logs.
Tim Shelton (HAWK.IO), Huntrule TeamWindowssecurityMedium3510Free2021-12-06Windows sc.exe Service Query Execution via Process Creation
Flags sc.exe executions with command lines containing " query", consistent with Windows service information discovery.
frack113, Huntrule TeamWindowsprocess_creationLow80Free2021-12-06Windows System Logs: Windows Update Client errors (connection, install, uninstall, revert, commit)
Alerts on Windows Update Client errors in System logs, including connection, install, uninstall, revert, and commit failures.
frack113, Huntrule TeamWindowssystemInformational198Free2021-12-04Windows Process Command Line Containing Whoami as First Parameter
Flags Windows process creations with command lines containing '.exe whoami' to surface potential discovery behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2021-11-29Windows Regsvr32.exe Executed with Suspicious File Extension Masquerading as DLL
Alerts when REGSVR32.exe runs with a command-line argument ending in a suspicious masquerade file extension.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh151Free2021-11-29Windows File Writes from NPPSpy Hacktool: NPPSpy.txt and NPPSpy.dll
Alerts on Windows file events writing NPPSpy.txt or NPPSpy.dll, consistent with credential dumping by the NPPSpy hacktool.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh102Free2021-11-29Linux auditd: getcap scanning for setuid/setgid-capable files under root
Flags getcap command-line usage scanning / for Linux capability-bearing files via auditd.
Pawel Mazur, Huntrule TeamLinuxauditdLow153Free2021-11-28Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
Florian Roth (Nextron Systems), Samir Bousseaden, Huntrule TeamWindowsprocess_creationCritical382Free2021-11-27Windows Process Access to LSASS Memory From Suspicious Source Paths
Alerts on processes attempting sensitive access to lsass.exe originating from suspicious/temp directories, using granted access and source path context.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessMedium70Free2021-11-27