Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Service stop activity via net.exe command line
Flags Windows processes running net.exe/net1.exe with a command line containing ' stop ' to stop a service.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow100Free2023-03-05Windows: Root Certificate Added Using certutil.exe -addstore
Flags certutil.exe executions that use -addstore with root-related parameters to install a certificate.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationMedium379Free2023-03-05Windows: Root Certificate Installation via CertMgr.EXE (/add root)
Flags CertMgr.EXE used to add a root certificate on Windows by matching /add and root in the command line.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationMedium111Free2023-03-05Windows PowerShell Set-Service StartupType Change to Disabled or Manual
Alerts on PowerShell Set-Service commands changing a service startup type to Disabled or Manual on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium227Free2023-03-04Windows whoami.exe Execution With /FO CSV or Output Redirection
Detects whoami.exe runs that request CSV output or indicate output redirection for saved results.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2023-02-28Windows whoami.exe Group Membership Reconnaissance via /groups Flag
Flags whoami.exe runs that use the /groups option to enumerate current user group memberships and SIDs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-02-28Windows sc.exe Service Security Descriptor Tampering (sdset)
Detects sc.exe executions using sdset to modify service security descriptors, enabling stealthy service tampering.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-02-28Windows sc.exe Service Security Descriptor Changes via sdset
Alerts on sc.exe sdset activity that modifies a service security descriptor to grant access to targeted principals.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2023-02-28Windows Firewall Exception Rule Added for Application in Suspicious Path
Flags new Windows Defender Firewall exception rules for apps located in Temp/PerfLogs/Public/Tasks-like directories.
frack113, Huntrule TeamWindowsfirewall-asHigh81Free2023-02-26Windows wscript.exe DNS Queries to Potentially Malicious Hex-Label Domains
Alerts when wscript.exe triggers DNS lookups for domains matching a C2-like regex pattern.
Dusty Miller, Huntrule TeamWindowsdns_queryHigh162Free2023-02-23Joomla Webserver: Potential CVE-2023-23752 Exploitation via GET public=true on /api/index.php/v1/
Alerts on GET requests to Joomla API paths with 'public=true' query parameters commonly associated with CVE-2023-23752 probing.
Bhabesh Raj, Huntrule Team—webserverHigh111Free2023-02-23Windows: Mounting Internet Hosted WebDAV Shares via net.exe
Alerts on net.exe (net1.exe) commands that mount an HTTP/WebDAV network share.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2023-02-21Windows New Service Creation via sc.exe
Flags sc.exe service creation commands containing create and binPath on Windows, excluding Dropbox-launched cases.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow438Free2023-02-20PowerShell Creates Windows Service via New-Service and -BinaryPathName
Flags PowerShell command lines that use New-Service with -BinaryPathName to create a Windows service.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow372Free2023-02-20macOS: Guest account enabled via sysadminctl
Flags sysadminctl command lines that appear to activate the macOS guest account.
Sohan G (D4rkCiph3r), Huntrule TeamMacosprocess_creationLow323Free2023-02-18