Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,109 rules
Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Alerts on Windows named pipe creations matching credential dumping tool pipe names.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowspipe_createdCritical375Free2019-11-01Windows Credential Dump Tool Artifacts Written to Disk via File Events
Detects Windows file creation where the target filename contains or ends with known credential-dump tool or output names.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsfile_eventHigh257Free2019-11-01Windows Security: Suspicious AccessMask/AccessList Requested on LSASS (lsass.exe) Handle
Flags processes requesting potentially credential-dumping-related access to LSASS based on Security Event 4656/4663.
Roberto Rodriguez, Teymur Kheirkhabarov, Dimitrios Slamaris, Mark Russinovich, Aleksey Potapov, oscd.community (update), Huntrule TeamWindowssecurityMedium184Free2019-11-01Windows Security: Suspicious Local Account Created with ANONYMOUS LOGON SamAccountName
Alerts on Windows local account creation where the new SamAccountName contains “ANONYMOUS” and “LOGON”.
James Pemberton / @4A616D6573, Huntrule TeamWindowssecurityHigh40Free2019-10-31Windows PowerShell Script Execution from Alternate Data Stream (ADS)
Flags PowerShell processes using Get-Content -Stream to execute or retrieve script content from an ADS.
Sergey Soldatov, Kaspersky Lab, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2019-10-30Windows Process Creation Matching Mustang Panda Dropper Command-Line and winwsh.exe
Alerts on Windows process creation with temp-based wtaks/winwsh execution and script-launch command-line parameters.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationHigh103Free2019-10-30Windows process creation: Suspicious Dtrack RAT ping and network recon commands
Alerts on Windows command-line reconnaissance patterns resembling Dtrack RAT activity.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical82Free2019-10-30Windows Image Load: Unsigned dbghelp.dll/dbgcore.dll Loaded by Suspicious Process
Alerts on unsigned loading of dbghelp.dll/dbgcore.dll, often associated with memory dump creation and credential-access workflows.
Perez Diego (@darkquassar), oscd.community, Ecco, Huntrule TeamWindowsimage_loadHigh348Free2019-10-27Windows Remote Thread Creation Triggered by Uncommon Source Images
Detects remote thread creation on Windows when the SourceImage is one of several uncommon executables.
Perez Diego (@darkquassar), oscd.community, Huntrule TeamWindowscreate_remote_threadMedium404Free2019-10-27Windows Remote Thread Creation from Uncommon Parent Image
Alerts on remote thread creation on Windows when the source executable is rare, with exclusions for known benign image pairings.
Perez Diego (@darkquassar), oscd.community, Huntrule TeamWindowscreate_remote_threadHigh342Free2019-10-27Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Alert on Windows executions where a SYSTEM-integrity child is spawned by a LOCAL SERVICE or NETWORK SERVICE parent, excluding a specific rundll32 pattern.
Teymur Kheirkhabarov, Roberto Rodriguez (@Cyb3rWard0g), Open Threat Research (OTR), Huntrule TeamWindowsprocess_creationHigh209Free2019-10-26Windows: sc.exe Service Configuration Changed by Medium-Integrity Users
Alerts on sc.exe runs from Medium-integrity users that include service config/binPath or failure command changes.
Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh111Free2019-10-26Windows Service Configuration Tampering by Medium-Integrity Processes
Alerts on medium-integrity processes running commands that target registry service configuration values for potential privilege escalation.
Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh163Free2019-10-26Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Alerts when services.exe spawns cmd/%COMSPEC% commands writing to a named pipe consistent with getsystem behavior.
Teymur Kheirkhabarov, Ecco, Florian Roth, Huntrule TeamWindowsprocess_creationHigh228Free2019-10-26Windows: DXCap.exe Used with -c to Launch Arbitrary Binaries
Flags Windows executions of DXCap.EXE using -c, a pattern that can launch arbitrary binaries or packages.
Beyu Denis, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium62Free2019-10-26