Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Microsoft 365 Threat Management: PST Export via New-ComplianceSearchAction -Export
Flags M365 SecurityComplianceCenter activity that includes New-ComplianceSearchAction with -Export for PST content.
Nikita Khalimonenkov, Huntrule TeamM365threat_managementMedium163Free2022-11-17Windows file activity matching CrackMapExec/Impacket-secretsdump credential dumping temp output patterns
Alerts on Windows temp file creations consistent with CrackMapExec or Impacket-secretsdump credential dumping activity.
SecurityAura, Huntrule TeamWindowsfile_eventHigh3010Free2022-11-16Windows Driver Load: Process Hacker (processhacker.sys) Presence
Flags Windows driver loads of Process Hacker’s processhacker.sys using path and known imphash indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh143Free2022-11-16Windows Process Creation: Suspicious RunAs-Like Command-Line Flag Combination
Flags Windows processes with both target-user and target-command flags in the same command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium91Free2022-11-11PowerShell Get-ADComputer Export of Active Directory Computer Data to File (Windows)
Detects PowerShell running Get-ADComputer (* filter) and exporting results to a file via output/content cmdlets.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-11-10Windows: Detect sftp.exe used as a LOLBIN via -D option
Alerts on Windows executions of sftp.exe using the -D flag with a path argument.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium163Free2022-11-10Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Alerts on Windows Code Integrity Event ID 3077 when an image/driver load is blocked for signing-level or policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh151Free2022-11-10Windows Process Creation: Sysmon.exe as Parent of Spawned Process
Alerts when Sysmon.exe/Sysmon64.exe is the parent of a new process, a potentially suspicious execution chain on Windows.
Florian Roth (Nextron Systems), Tim Shelton (fp werfault), Huntrule TeamWindowsprocess_creationHigh102Free2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-11-09Windows System: Kerberos KDC RC4-HMAC downgrade exploit attempts (CVE-2022-37966)
Identifies Windows Kerberos KDC error events tied to RC4-HMAC downgrade/auth negotiation exploitation behavior (CVE-2022-37966).
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh148Free2022-11-09Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
Tim Rauch, Janantha Marasinghe, Elastic (original idea), Huntrule TeamWindowsprocess_creationHigh112Free2022-11-08Windows File Creation: Suspicious LNK Double-Extension Targeted by Document/Image Prefixes
Alerts on Windows-created filenames that end in .lnk while containing hidden-looking double extensions (e.g., .doc. .pdf.)
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsfile_eventMedium103Free2022-11-07Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Identifies Windows successful logons consistent with potential access token impersonation using Advapi and Negotiate.
Michaela Adams, Zach Mathis, Huntrule TeamWindowssecurityMedium60Free2022-11-06Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
Ilya Krestinichev, Huntrule TeamWindowsprocess_creationHigh131Free2022-11-03Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh152Free2022-11-03