Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Windefend: Defender Restored File from Quarantine (EventID 1009)
Alerts on Windows Defender Windefend events indicating an item was restored from quarantine (Event ID 1009).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh91Free2022-12-06Windows Defender SubmitSamplesConsent Disabled (Real-Time Protection)
Flags Windows Defender configuration changes disabling automatic sample submission (SubmitSamplesConsent=0x0).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendLow349Free2022-12-06Windows Process Creation: Command Line Contains Emoji Characters
Alerts on Windows process executions whose command line includes emoji/symbol characters from a predefined list.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh2410Free2022-12-05Windows Process Command Line Contains Emoji Characters
Alerts when a Windows process command line includes emoji characters, which can be used to obscure activity or bypass naive detections.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh121Free2022-12-05Windows Process Creation: Command Line Contains Specific Emoji Characters
Alerts when a Windows process command line includes specific emoji Unicode characters that may be used for evasion or obfuscation.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh195Free2022-12-05Windows Process Creation Command-Line Contains Emoji Characters
Alerts on Windows executions whose command line includes emoji Unicode characters.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh289Free2022-12-05Windows: Elevated PowerShell or CMD Spawned from Uncommon Parent Location
Alerts on elevated PowerShell/CMD executions whose parent process comes from uncommon Windows locations, indicating likely privilege escalation.
frack113, Tim Shelton (update fp), Huntrule TeamWindowsprocess_creationMedium172Free2022-12-05Windows Process Creation: Renamed Mavinject32/64.EXE Execution
Alerts on renamed executions of mavinject32.exe/mavinject64.exe based on OriginalFileName and image path.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh239Free2022-12-05Windows Scheduled Task Execution of Uncommon Binaries (LOLBin Suspicion)
Alerts when a Windows Scheduled Task runs a process from a set of uncommon/suspicious binary paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowstaskschedulerMedium163Free2022-12-05Windows Scheduled Task Process Run from Suspicious File Locations
Alerts on Windows Task Scheduler process creation when the executed program runs from temp, downloads, desktop, or public-writable paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowstaskschedulerMedium396Free2022-12-05Windows Security: Suspicious Scheduled Task Update via Event ID 4702 Keywords
Alerts when a scheduled task is updated (EventID 4702) and the new task content includes suspicious execution keywords or temp/user paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh141Free2022-12-05Windows Security Audit: Scheduled Task Deleted or Disabled (Important Task Names)
Alerts on deletion or disabling of important Windows scheduled tasks based on Security audit events 4699 and 4701.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh445Free2022-12-05Windows Security: Suspicious Scheduled Task Creation via Event 4698
Alerts on Windows scheduled task creation (EventID 4698) when TaskContent contains suspicious directories or command patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh113Free2022-12-05Windows Process Creation: SysmonEOP.exe HackTool Execution (CVE-2022-41120 PoC)
Alert on Windows process execution of \SysmonEOP.exe with specific IMPhashes associated with the SysmonEOP PoC.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical208Free2022-12-04Windows Process Execution of wsudo with System or TrustedInstaller
Alerts on wsudo.exe runs from wsudo-bridge.exe requesting execution as System or TrustedInstaller.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2022-12-02