Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
70 rules
Windows: Unsigned DLL/EXE Image Loaded Into lsass.exe
Alerts on image loads into lsass.exe where the loaded image is unsigned.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsimage_loadMedium151Free2019-10-22Windows Security Log LSASS Access by Non-Computer Account Process
Alerts on suspicious LSASS access attempts (4663/4656) targeting lsass.exe by non-system processes using flagged access masks.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium3710Free2019-06-20WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
Patryk Prauze - ING Tech, Huntrule TeamWindowsprocess_accessHigh239Free2019-05-20Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
vburov, Huntrule TeamWindowsprocess_creationLow162Free2019-02-23Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2018-10-30Windows LSASS process access blocked by Attack Surface Reduction (Windows Defender event 1121)
Alerts on windefend EventID 1121 for blocked access to lsass.exe, excluding common benign process callers.
Markus Neis, Huntrule TeamWindowswindefendHigh171Free2018-08-26Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
Markus Neis, Huntrule TeamWindowsfile_eventHigh203Free2018-07-24Windows LSASS Remote Thread Creation Indicative of Password Dumping
Flags Windows remote thread creation targeting lsass.exe, a common pattern in password dumping activity.
Thomas Patzke, Huntrule TeamWindowscreate_remote_threadHigh427Free2017-02-19Windows Security: Detect LSASS handle access for SAM_DOMAIN (0x705)
Flags handle opens to lsass.exe with access mask 0x705 targeting SAM_DOMAIN, indicative of credential dumping.
sigma, Huntrule TeamWindowssecurityHigh102Free2017-02-12Windows WerFault Access to lsass.exe Indicative of Credential Dumping Attempts
Alert on WerFault.exe gaining broad access to lsass.exe, consistent with credential dumping attempts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh223Free2012-06-27