Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,191 rules
Windows Process UAC Bypass via Windows Media Player osksupport.dll (osk.exe → cmd.exe)
Alerts on osk.exe spawning cmd.exe under mmc event viewer with high/system integrity, consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2021-08-23Windows UAC Bypass via pkgmgr.exe Launching dism.exe (High/System Integrity)
Detects pkgmgr.exe spawning dism.exe with High/System integrity levels on Windows, a pattern used in UAC bypass attempts.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh418Free2021-08-23Windows UAC Bypass via consent.exe and werfault.exe with comctl32.dll-related behavior
Alerts on consent.exe parent launching werfault.exe with high/system integrity levels, consistent with potential UAC bypass attempts.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh285Free2021-08-23Windows UAC bypass via changepk.exe launched from slui.exe with elevated integrity
Flags changepk.exe execution from slui.exe with High/System integrity to identify potential UAC bypass behavior on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2021-08-23Windows Process Creation: Suspicious splwow64.exe Missing Command-Line Parameters
Flags Windows executions of splwow64.exe where the command line ends at the executable with no parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2021-08-23Windows UAC Bypass via WoW64 Logger DLL Hijack (Process Access Pattern)
Flags SysWOW64 process-access behavior with high granted access and unknown call traces consistent with a WoW64 logger DLL hijack UAC bypass.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh112Free2021-08-23PowerShell discovery of Win32_PnPEntity via ScriptBlockText
Alerts when PowerShell script blocks reference Win32_PnPEntity to enumerate attached Plug and Play devices.
frack113, Huntrule TeamWindowsps_scriptLow373Free2021-08-23Windows Named Pipe Creation Matching EfsPotato-Style \\pipe\\srvsvc
Alerts on Windows named pipe creation events matching an EfsPotato-style PipeName pattern (\pipe\ and \pipe\srvsvc), excluding common benign contexts.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdHigh131Free2021-08-23UAC Bypass via Windows Media Player: DllHost.exe spawning osk.exe writing OskSupport.dll to Temp
Flags file events where Temp\OskSupport.dll is targeted alongside DllHost.exe and Windows Media Player\osk.exe, consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh82Free2021-08-23Windows UAC Bypass via consent.exe with comctl32.dll file path pattern
Detects suspicious target path patterns involving consent.exe.@ and comctl32.dll consistent with UAC bypass staging.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2021-08-23Windows Office Applications Creating Executable/Script Files with Suspicious Extensions
Flags Office application processes creating .exe/.dll/.ps1 and other script or executable files on Windows.
Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh367Free2021-08-23Exchange Management: Certificate CSR exported to webserver or .aspx-named path
Flags Exchange CSR export commands that write request files to C$ and web-root paths or use an .aspx filename.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical152Free2021-08-23M365 Threat Management: Suspicious OAuth App File Downloads from SharePoint or OneDrive
Alerts on unusual bulk file downloads by a Microsoft 365 OAuth app from SharePoint or OneDrive.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium303Free2021-08-23Microsoft 365 Cloud Apps: Successful login from a risky IP address
Alerts on successful sanctioned-app logons from risky IP addresses reported in M365 SecurityComplianceCenter.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium92Free2021-08-23Microsoft 365 SecurityComplianceCenter: Exfiltration Activity to Unsanctioned Apps
Alerts on successful Cloud App Security reports of data exfiltration attempts using unsanctioned apps.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium111Free2021-08-23