Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,090 rules
Uncommon PowerShell HostApplication Values in Windows PowerShell Start Logs
Detects PowerShell classic start events with unusual HostApplication values that may indicate evasion of powershell.exe-focused detections.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsps_classic_startMedium30Free2019-08-11Windows CreateRemoteThread with LoadLibraryA likely DLL injection
Alerts on CreateRemoteThread starting LoadLibraryA from kernel32.dll, consistent with DLL injection attempts.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowscreate_remote_threadMedium30Free2019-08-11Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowsps_moduleHigh103Free2019-08-10Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Flags Windows telemetry indicating a remote PowerShell session startup using wsmprovhost.exe with a specified host parameter.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsps_classic_startLow62Free2019-08-10Windows Security: Network Access to protected_storage (IPC)
Flags Windows network share access to protected_storage through IPC from Security event 5145.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh63Free2019-08-10Windows Security Event 4692 Detecting DPAPI Domain Master Key Backup Attempt
Flags Windows Event ID 4692 indicating an attempt to back up the DPAPI domain master key.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium214Free2019-08-10Windows Image Load: WMI DLLs Loaded by Uncommon Process
Alert on loading of common WMI DLLs by processes outside typical system/.NET paths.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsimage_loadLow50Free2019-08-10Windows: MMC spawning command-line executables
Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.
Karneades, Swisscom CSIRT, Huntrule TeamWindowsprocess_creationHigh101Free2019-08-05Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.
Nik Seetharaman, Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh322Free2019-07-31Windows Security: AD object replication attempted by non-machine account (Event ID 4662)
Alerts on AD replication-related object access events where the requester is not a machine account.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical103Free2019-07-26Windows regsvr32 Executes DLL with Uncommon Extension in Command Line
Alerts when regsvr32.exe is launched with a DLL extension pattern that is not in the common list.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium285Free2019-07-17Windows regsvr32 Usage of /i Without /n Flag
Alerts on regsvr32.exe invocations using /i: without the usually paired /n flag.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium166Free2019-07-13Windows: Explorer factory invocation causing process tree break
Alerts on process creation command lines showing explorer.exe factory and /root usage consistent with an explorer-based process tree break.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @gott_cyber, Huntrule TeamWindowsprocess_creationMedium84Free2019-06-29Windows Process Creation: Executable Extension Masquerading with .exe After Decoy Extension
Alerts on Windows processes whose paths/command lines use misleading double extensions ending in .exe to cloak executable execution.
Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2019-06-26Windows Security Log LSASS Access by Non-Computer Account Process
Alerts on suspicious LSASS access attempts (4663/4656) targeting lsass.exe by non-system processes using flagged access masks.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium3610Free2019-06-20