Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
146 rules
SharpHound RPC Firewall Recon: Remote Mapping and Group Membership Enumeration
Alerts on RPC Firewall EventID 3 for SharpHound-style discovery RPC calls to interface UUID with OpNum 12.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh112Free2022-01-01SharpHound Account Recon via RPC Firewall Block (OpNum 2, Interface UUID)
Alerts on RPC Firewall EventID 3 with the Interface UUID and OpNum used by SharpHound for account discovery.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh1710Free2022-01-01RPC Firewall Alerts for SASec Scheduled Task Discovery (SASec)
Identifies RPC Firewall alerts for SASec interface calls related to scheduled task discovery.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh477Free2022-01-01PowerShell Credential Discovery via Recursive File Search and Select-String
Flags PowerShell script blocks that recursively list files and run select-string pattern searches, indicative of credential hunting.
frack113, Huntrule TeamWindowsps_scriptMedium144Free2021-12-19Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
frack113, Huntrule TeamWindowsprocess_creationHigh403Free2021-12-16PowerShell Security Software Discovery Using get-process Piped to where-object (Windows)
Flags PowerShell scripts that enumerate processes and filter results for security software by vendor/product keywords.
frack113, Anish Bogati, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium161Free2021-12-16PowerShell ScriptBlock Enumeration of AD Group Membership and User Attributes (Windows)
Flags PowerShell script blocks querying AD group membership and user details for discovery of privileged directory information.
frack113, Huntrule TeamWindowsps_scriptLow351Free2021-12-15PowerShell Module: Get-SmbShare Used for SMB Share Discovery
Detects PowerShell module usage of Get-SmbShare to enumerate SMB shares across networked systems.
frack113, Huntrule TeamWindowsps_moduleLow465Free2021-12-15PowerShell module enumeration of AD principals via get-ADPrincipalGroupMembership
Flags PowerShell module usage of Get-ADPrincipalGroupMembership and Get-ADUser with -pr -f patterns indicative of AD discovery.
frack113, Huntrule TeamWindowsps_moduleLow234Free2021-12-15Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
frack113, Huntrule TeamWindowsprocess_creationHigh245Free2021-12-13Windows Process Discovery via wmic.exe "group" Flag
Flags wmic.exe process executions querying local group information via a "group" command-line argument.
frack113, Huntrule TeamWindowsprocess_creationLow298Free2021-12-12PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
frack113, Huntrule TeamWindowsps_scriptLow319Free2021-12-12PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
frack113, Huntrule TeamWindowsps_moduleLow111Free2021-12-12Windows Process Discovery via tasklist Command Execution
Alerts on Windows executions of tasklist.exe used for running process discovery.
frack113, Huntrule TeamWindowsprocess_creationInformational120Free2021-12-11Windows Process Creation: Nmap/Zenmap (nmap.exe or zennmap.exe) Execution
Flags Windows execution of Nmap/Zenmap (nmap.exe or zennmap.exe) used for remote service discovery.
frack113, Huntrule TeamWindowsprocess_creationMedium171Free2021-12-10