Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
146 rules
Windows Net.exe Network Connections Discovery via Use Sessions Query
Flags net.exe/net1.exe commands using 'use sessions' to enumerate network connection/session information.
frack113, Huntrule TeamWindowsprocess_creationLow130Free2021-12-10Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Alerts when SharpView.exe runs with command-line indicators of AD and network discovery/enumeration activity.
frack113, Huntrule TeamWindowsprocess_creationHigh172Free2021-12-10PowerShell Get-NetTCPConnection Network Connection Discovery (Windows)
Detects PowerShell use of Get-NetTCPConnection to enumerate TCP network connections for discovery.
frack113, Huntrule TeamWindowsps_moduleLow111Free2021-12-10Windows Process Creation: Suspicious Network Configuration and Discovery Commands
Alerts on Windows command-line usage of network configuration and discovery tools (ipconfig, netsh, arp, nbtstat, net config, route print).
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow203Free2021-12-07Windows netsh.exe Firewall Configuration Discovery (show firewall rule/state/name=all)
Flags netsh.exe commands used to enumerate Windows firewall rules and states via “show firewall … name=all”.
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow186Free2021-12-07Windows sc.exe Service Query Execution via Process Creation
Flags sc.exe executions with command lines containing " query", consistent with Windows service information discovery.
frack113, Huntrule TeamWindowsprocess_creationLow90Free2021-12-06Windows Process Command Line Containing Whoami as First Parameter
Flags Windows process creations with command lines containing '.exe whoami' to surface potential discovery behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-11-29Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
Detects stordiag.exe spawning schtasks.exe, systeminfo.exe, or fltmc.exe to support system discovery or config actions on Windows.
Austin Songer (@austinsonger), Huntrule TeamWindowsprocess_creationHigh132Free2021-10-21Linux Process Creation Webshell Tooling: Web Server Child Processes Running System Commands
Detects web server processes spawning Linux command-line tools commonly used for host discovery or persistence.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh203Free2021-10-15Linux auditd System Information Discovery via uname, uptime, lsmod, hostname, env, and release file reads
Triggers on auditd events showing host enumeration commands and system identity file access on Linux.
Pawel Mazur, Huntrule TeamLinuxauditdLow183Free2021-09-03PowerShell discovery of Win32_PnPEntity via ScriptBlockText
Alerts when PowerShell script blocks reference Win32_PnPEntity to enumerate attached Plug and Play devices.
frack113, Huntrule TeamWindowsps_scriptLow373Free2021-08-23PowerShell Virtualization Environment Discovery via WMI in ScriptBlockLogging (Windows)
Identifies PowerShell WMI queries for Win32 computer system and ACPI thermal data used to check virtualization environments.
frack113, Duc.Le-GTSC, Huntrule TeamWindowsps_scriptMedium354Free2021-08-03Windows Process Creation: Automated Document and Directory Discovery via dir and findstr
Flags Windows commands combining recursive dir listing, FINDSTR usage, and document-type targeting in one execution.
frack113, Huntrule TeamWindowsprocess_creationMedium264Free2021-07-28Windows nltest.exe Recon via Server Query and Domain Trust Enumeration
Alerts on nltest.exe commands with server/query and domain trust enumeration arguments often used for Windows discovery.
Craig Young, oscd.community, Georg Lauenstein, Huntrule TeamWindowsprocess_creationMedium163Free2021-07-24PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh315Free2021-07-16