Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows WMIC System Information Discovery via WMI Command-Line Queries
Flags WMIC command-line queries that pull OS, hardware, disk, memory, BIOS, and GPU details while excluding VMware Tools discovery scripts.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationLow90Free2023-12-19Windows Task Scheduler: SVR Scheduled Task Names (GraphicalProton) Matching
Flags Windows scheduled task creation, update, or deletion when task names match known SVR GraphicalProton backdoor strings.
CISA, Huntrule TeamWindowstaskschedulerHigh111Free2023-12-18Windows Scheduled Task Creation Using SVR-Specific Task Names
Alerts on Windows scheduled task events with SVR-associated task names indicative of persistence.
CISA, Huntrule TeamWindowssecurityHigh112Free2023-12-18Windows ImageLoad of SVR GraphicalProton DLL Names
Flags Windows DLL loads matching known GraphicalProton/SVR DLL filename suffixes.
CISA, Huntrule TeamWindowsimage_loadMedium457Free2023-12-18Windows Registry: Set LSA NoLMHash to 0 to Enable LM Hash Storage
Flags changes to NoLMHash (DWORD 0) enabling Windows to store LM password hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2023-12-15Windows Process Creation: Enable LM Hash Storage via Lsa\NoLMHash=0 in Command Line
Flags process command lines that set Lsa\NoLMHash to 0 to enable LM hash storage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh366Free2023-12-15Windows Registry: HVCI disallowed image list modified (HVCIDisallowedImages)
Alerts when Windows HVCI disallowed images registry value is modified, indicating potential driver load policy tampering.
Nasreddine Bencherchali (Nextron Systems), Omar Khaled (@beacon_exe), Huntrule TeamWindowsregistry_setHigh101Free2023-12-05Windows Process Creation: whoami.exe Executed With /all for Full Identity Enumeration
Detects Windows executions of whoami.exe using the /all flag to enumerate full identity details.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2810Free2023-12-04Windows process command line matches WinPwn tool execution keywords
Alerts on Windows process executions with command-line keywords associated with WinPwn (WinPwn.exe/ps1/offline mode).
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh276Free2023-12-04Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsps_scriptHigh152Free2023-12-04Linux dd Process Memory Map Overwrite for Code Injection (proc/mem)
Alerts when dd is used to write to /proc/<pid>/mem, suggesting potential Linux process code injection.
Joseph Kamau, Huntrule TeamLinuxprocess_creationMedium121Free2023-12-01Windows Registry Set in Shell Open Command Using PowerShell Cryptography .NET Classes
Flags registry set of \Shell\Open\Command where PowerShell references System.Security.Cryptography crypto classes.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsregistry_setMedium50Free2023-12-01PowerShell Crypto Namespace Class Invocation for Windows Process Creation
Alerts on PowerShell executions that reference System.Security.Cryptography and common crypto class names.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationMedium60Free2023-12-01Windows Registry: Netsh Helper DLL value added under SOFTWARE\Microsoft\NetSh
Alerts on Windows registry writes under SOFTWARE\Microsoft\NetSh that add .dll helper entries.
Anish Bogati, Huntrule TeamWindowsregistry_setMedium151Free2023-11-28Windows: Netsh helper DLL registration via suspicious registry paths
Flags Netsh helper DLL registration when the DLL path is found in suspicious user/temp-like registry details on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh82Free2023-11-28