Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,169 rules
Windows: Suspicious Child Process Spawned by scrcons.exe (Script Event Consumer)
Alerts on rare child processes spawned by scrcons.exe, which may indicate abuse of Script Event Consumer for execution.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh383Free2021-06-21Windows Registry: New TaskCache entry created by unusual process image
Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.
Syed Hasan (@syedhasan009), Huntrule TeamWindowsregistry_setHigh212Free2021-06-18Windows Execution of PurpleSharp HackTool by Image Name or Executable Metadata
Alerts on process creation events consistent with running PurpleSharp.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical181Free2021-06-18Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.
MSTIC, FPT.EagleEye, Huntrule TeamWindowsprocess_creationHigh183Free2021-06-15Windows: Process writes registry to disable storage write-protection
Alerts on Windows process command lines that appear to disable storage write-protection via registry modification.
Sreeman, Huntrule TeamWindowsprocess_creationMedium181Free2021-06-11Windows Registry Set—Custom Outlook Today Page for Persistence
Flags registry writes that configure a custom Outlook Today URL using Outlook Today registry values.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh339Free2021-06-10Windows Persistence Attempt Using Outlook.exe to Create Outlook Forms Cache
Flags Outlook (outlook.exe) form file activity targeting local FORMS directories often used for persistence.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsfile_eventHigh201Free2021-06-10Windows Registry Changes for Outlook WebView Home Page URL Persistence
Alerts on Windows registry modifications affecting Outlook WebView home page URL settings.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh454Free2021-06-09BabyShark HackTool Proxy C2 URL Pattern via momyshark?key=
Alerts on proxy URIs containing the BabyShark agent default "momyshark?key=" query pattern.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical123Free2021-06-09Windows Registry: Microsoft Office Protected View Disabled via Security Policy Keys
Flags Windows registry updates that disable Microsoft Office Protected View for attachments, internet files, UNC paths, or unsafe locations.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh252Free2021-06-08Windows Process Creation: Exchange Transport Agent Installation via Install-TransportAgent
Flags Windows command-line executions containing Install-TransportAgent, indicating Exchange Transport Agent installation activity.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium241Free2021-06-08Windows MSExchange: Failed Transport Agent Installation (Install-TransportAgent)
Alerts on EventID 6 Exchange management events that include "Install-TransportAgent", indicating a failed Transport Agent installation attempt.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh4210Free2021-06-08Windows MSExchange Transport Agent Installation via Install-TransportAgent
Flags Exchange Transport Agent installation attempts using the Install-TransportAgent command in MSExchange management telemetry.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsmsexchange-managementMedium503Free2021-06-08Windows AMSI Provider Registry Key Deletion (HKLM\Software\Microsoft\AMSI)
Alerts on deletion of AMSI provider registry key entries under HKLM\Software\Microsoft\AMSI, potentially indicating AMSI inspection impairment.
frack113, Huntrule TeamWindowsregistry_deleteHigh172Free2021-06-07PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_classic_provider_startHigh403Free2021-06-07