Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Uncommon Process Creates .rdp Remote Desktop File
Alerts on creation of .rdp files by processes that are not typically associated with producing them on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-04-18Windows winget Install from Zone.Identifier/WinGet Temp Contents Marked by Zone Transfer
Alerts on winget staging under Temp\WinGet combined with ZoneTransfer ZoneId=3 and Zone.Identifier ADS contents.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh152Free2023-04-18Windows Registry: Winget EnableLocalManifestFiles Set to DWORD 1
Flags setting the Winget AppInstaller local manifest installation policy (EnableLocalManifestFiles) to enabled.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium151Free2023-04-17Windows winget AppInstaller admin_settings registry modification via winget.exe
Detects winget.exe-driven changes to AppInstaller admin_settings in the registry under LocalState\admin_settings.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow413Free2023-04-17Windows Process: winget adds new download source via 'source add' with IP/endpoint
Alerts on winget.exe being used to add a new package download source specified by an IP address.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-04-17Windows Winget adds HTTP package source
Alerts when winget is used to add a package source pointing to an http:// URL.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-04-17Windows: winget.exe adds new download sources via 'source add'
Alerts on winget.exe usage to add new package download sources using 'source add'.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-04-17Windows Process Creation: Crassus Privilege Escalation Discovery Tool Execution
Identifies execution of the Crassus Windows privilege escalation discovery tool via process metadata.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh278Free2023-04-17Windows: Stracciatella.exe Process Execution Identification (SharpPick behavior)
Alerts on Windows process creation for Stracciatella.exe using PE metadata and known SHA256 hashes.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-04-17Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Flags Certipy.exe execution on Windows using PE metadata and Certipy-like AD CS command-line arguments.
pH-T (Nextron Systems), Sittikorn Sangrattanapitak, Huntrule TeamWindowsprocess_creationHigh319Free2023-04-17Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Identifies Windows processes running Certify.exe with AD certificate abuse-oriented command line arguments.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2023-04-17Windows image_load Suspicious libvlc.dll DLL sideloading via non-VLC paths
Alerts when libvlc.dll is loaded from a non-default path, suggesting potential VLC DLL sideloading on Windows.
X__Junior, Huntrule TeamWindowsimage_loadMedium133Free2023-04-17Windows: Unexpected Termination of Message Queuing (MSMQ) Service via SCM Event 7034
Flags Service Control Manager Event ID 7034 for unexpected termination of the Message Queuing (MSMQ) service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh241Free2023-04-14Windows Service Control Manager: Termination of Security-Critical Services With Error
Alerts on error-terminated Windows security and infrastructure services from Service Control Manager event 7023.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh182Free2023-04-14Windows Service Terminated With Error (Service Control Manager Event 7023)
Alerts on Windows services terminated with an error as reported by the Service Control Manager (EventID 7023).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemLow130Free2023-04-14