Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,096 rules
Windows Process Creation: File/Folder Permission Changes via cacls/icacls/net attrib/takeown
Alerts when Windows permission/ownership changes are attempted using ACL and ownership tools with grant/inheritance-related command-line flags.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium40Free2019-10-23Windows Raw Disk Access by Uncommon Process Paths
Alerts on Windows raw disk access by processes from uncommon or suspicious locations.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsraw_access_threadLow51Free2019-10-22Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh81Free2019-10-22Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationMedium325Free2019-10-22Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Flags reg.exe command lines exporting or saving HKLM registry hives tied to SAM, SYSTEM, and SECURITY.
Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh3510Free2019-10-22Windows Process Execution Matching SILENTTRINITY Stager Metadata (st2stager)
Flags Windows process creation events containing "st2stager" in PE metadata, indicating SILENTTRINITY stager activity.
Aleksey Potapov, oscd.community, Huntrule TeamWindowsprocess_creationHigh139Free2019-10-22Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Flags Windows processes whose command lines contain Mimikatz names and credential-dumping module/function arguments.
Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh123Free2019-10-22Windows: Detect esentutl.exe Copying Sensitive Credential Files via VSS
Alerts on esentutl.exe VSS usage and command lines referencing SAM/SECURITY/SYSTEM or ntds.dit copy targets.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh92Free2019-10-22Windows Volume Shadow Copy Symlink Creation Using mklink
Flags Windows mklink commands that reference HarddiskVolumeShadowCopy to create symlinks.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh103Free2019-10-22Windows: Unsigned DLL/EXE Image Loaded Into lsass.exe
Alerts on image loads into lsass.exe where the loaded image is unsigned.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsimage_loadMedium121Free2019-10-22Windows Static Webshell Indicators via Suspicious File Extension Creation in Web Roots
Alerts on Windows creation of script-like files with webshell extensions in web root directories, excluding common benign temp and XAMPP paths.
Beyu Denis, oscd.community, Tim Shelton, Thurein Oo, Huntrule TeamWindowsfile_eventMedium102Free2019-10-22Windows Network Share File Transfers Targeting Credential and Memory Dump Paths
Alerts on network share access to credential-related files using Windows Security Event 5145.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowssecurityMedium144Free2019-10-22Rundll32.exe DLL Export Calls by Ordinal (Windows Process Creation)
Detects rundll32.exe commands that specify DLL exports by ordinal using “.dll #” syntax.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium100Free2019-10-22Windows Network Tool Use for Possible Packet Sniffing (tshark/windump)
Alerts on Windows executions of tshark or windump that indicate potential passive network traffic capture.
Timur Zinniatullin, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium73Free2019-10-21Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow315Free2019-10-21