Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
PowerShell Script Block: SMB QUIC Share Mapping via New-SmbMapping
Alerts when PowerShell maps Windows SMB shares using New-SmbMapping with -TransportType QUIC.
frack113, Huntrule TeamWindowsps_scriptMedium70Free2023-07-21Windows Sysmon FileExecutableDetected (Event ID 29) Alerts on New Executable Files
Alerts on any Sysmon Event ID 29 indicating a new monitored executable file was created on Windows.
frack113, Huntrule TeamWindowssysmonMedium438Free2023-07-20Sysmon FileBlockShredding Policy Violations (Event ID 28) on Windows
Alerts on Sysmon Event ID 28 when file shredding is blocked by the configured shredding policy on Windows.
frack113, Huntrule TeamWindowssysmonHigh387Free2023-07-20Windows Process Creation: schtasks.exe Creating Scheduled Task Launching Registry-Stored PowerShell Payload
Flags schtasks.exe /Create scheduled tasks that launch PowerShell decoding and executing a base64 payload retrieved from Windows Registry.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-07-18Windows netsh.exe Advanced Firewall Rule Set Modification
Flags netsh.exe command lines that invoke advfirewall firewall set to modify existing Windows firewall rule properties.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2023-07-18Windows Process Creation: One-liner cmd.exe CommandLine with ping and copy
Alerts when cmd.exe runs a one-liner that includes both ping and copy with expected options.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2023-07-18Windows PowerShell Script Modifies File Permissions with Set-Acl
Flags PowerShell scripts that call Set-Acl to change ACL permissions on a specified path.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow80Free2023-07-18Windows: Detect Cmd.exe Redirection of Discovery Commands by Ursnif
Flags explorer-launched cmd.exe commands that use /C and redirect output to AppData local temp .bin files.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh336Free2023-07-16Windows PowerShell WMI Win32_NTEventlogFile Calls with Event Log Tampering Methods
Flags PowerShell calling Win32_NTEventlogFile WMI methods commonly used to clear, delete, backup, or alter Windows event logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2023-07-13Suspicious PowerShell WMI Win32_NTEventlogFile Usage (Event Log Tampering)
Detects PowerShell scripts calling Win32_NTEventlogFile methods associated with event log deletion, backup, renaming, or permission changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium153Free2023-07-13Windows DLL Sideloading: CCleanerReactivator.dll Loaded from CCleaner Directories
Identifies potential CCleanerReactivator.dll DLL sideloading when loaded by CCleanerReactivator.exe outside expected CCleaner paths.
X__Junior, Huntrule TeamWindowsimage_loadMedium228Free2023-07-13Windows DLL Sideloading via CCleanerDU.dll ImageLoad from CCleaner Folder
Alerts when CCleanerDU.dll is loaded, but the loading image is not CCleaner executables in standard install paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium142Free2023-07-13PowerShell NetFirewallRule Cmdlet Enumeration of Local Windows Firewall Rules
Flags PowerShell attempts to enumerate local Windows firewall rules via Get-NetFirewallRule or Show-NetFirewallRule.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsps_moduleLow80Free2023-07-13Windows Security 5140 File Share Access to MSHTML_C7 IP-Named Paths
Alerts on Windows file share access events targeting \MSHTML_C7\ shares with an IP-like naming pattern (EventID 5140).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh132Free2023-07-13Windows Office Recent Folder Dropped URL File (file001.url) Creation
Alerts on creation of file001.url in Microsoft Office Recent under C:\Users\, indicating potential exploit staging.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventMedium101Free2023-07-13