Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Scheduled Task File Creation Activity (File Event)
Flags file creation under Windows scheduled task directories that may indicate new scheduled task persistence.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowsfile_eventLow80Free2023-09-27Windows: AddInUtil.exe LoLBin Executed from Non-Standard Directory
Alerts when AddInUtil.exe (AddInUtil.exe) runs from an uncommon directory path on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium184Free2023-09-18Windows Process Creation: Uncommon AddInUtil.exe Use of AddInRoot/PipelineRoot Paths
Alerts on AddInUtil.exe runs where AddInRoot/PipelineRoot command-line paths deviate from common VSTA locations.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium259Free2023-09-18Windows: Uncommon Child Processes Spawned by Addinutil.exe
Alerts when Addinutil.exe launches an uncommon child process, indicating potential proxy execution abuse.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium273Free2023-09-18Windows AddInUtil.exe Executed with Suspicious AddInRoot or PipelineRoot Parameters
Alerts on AddInUtil.exe runs using uncommon AddInRoot/PipelineRoot values targeting Temp, Desktop, Downloads, or public user paths.
Nasreddine Bencherchali (Nextron Systems), Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationHigh102Free2023-09-18Windows network connections initiated by AddinUtil.exe
Alerts on network connections initiated by Addinutil.exe, which is uncommon for this utility on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsnetwork_connectionHigh431Free2023-09-18Microsoft 365 Audit: New Federated Domain Added
Alerts on Microsoft 365 audit events indicating a new federated domain was added.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditMedium113Free2023-09-18Microsoft 365 Audit: Disabling Strong Authentication (MFA)
Flags Microsoft 365 audit events indicating MFA/strong authentication was disabled.
Splunk Threat Research Team (original rule), Harjot Singh @cyb3rjy0t (sigma rule), Huntrule TeamM365auditHigh386Free2023-09-18Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths
Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-09-15Windows Diskshadow Script Mode Executes Script File with Uncommon .txt Extension
Alerts when diskshadow.exe runs with -s script mode and the script path/command includes an uncommon extension like .txt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium321Free2023-09-15Suspicious Child Process Spawned by Diskshadow.exe (Windows Process Creation)
Alerts on process creation where Diskshadow.exe spawns certutil, cscript, mshta, PowerShell, regsvr32, rundll32, or wscript.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-09-15Windows Diskshadow.exe Child Process Execution
Alerts when Diskshadow.exe is the parent process of a newly created process on Windows.
Harjot Singh @cyb3rjy0t, Huntrule TeamWindowsprocess_creationMedium80Free2023-09-15Windows File Access to .reg and .hive Backups by Uncommon Applications
Alerts on access to .hive/.reg files from less-common application paths on Windows.
frack113, Huntrule TeamWindowsfile_accessLow80Free2023-09-15Azure Entra PIM Alerts: Too Many Global Administrators Assigned to Tenant
Alerts when Azure PIM reports an overabundance of Global Administrator role assignments in a tenant.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh103Free2023-09-14Azure AD PIM Redundant Assignment Alert When Privileged Role Not Used
Alerts on Azure PIM redundant privileged role assignments where the assigned role appears unused.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzurepimHigh303Free2023-09-14