Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Driver Load of Known Vulnerable Drivers by File Name
Alerts when Windows loads a driver whose filename matches a list of known vulnerable drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadLow133Free2022-10-03Windows Malicious Driver Load Identified by Known Bad Driver File Names
Alerts when Windows loads a driver whose file name matches a curated list of known malicious/suspicious drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadMedium152Free2022-10-03Windows Registry: Disable Privacy Settings Experience via DisablePrivacyExperience Policy
Flags Windows registry policy changes that disable the Privacy Settings Experience by setting DisablePrivacyExperience to 0x00000000.
frack113, Huntrule TeamWindowsregistry_setMedium141Free2022-10-02Windows: Process creation of UltraVNC VNCViewer (VNCViewer.exe)
Flags execution of UltraVNC VNCViewer.exe on Windows based on process creation metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium234Free2022-10-02Windows Registry: Modify User Shell Folders Startup Values for Persistence
Alerts on Windows Registry changes to User Shell Folders startup-related values that may be used to establish persistence.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh393Free2022-10-01Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Flags w3wp.exe-launched commands matching China Chopper webshell execution patterns in Windows process creation logs.
Florian Roth (Nextron Systems), MSTI (query), Huntrule TeamWindowsprocess_creationHigh281Free2022-10-01Windows Suspicious Use of shutdown.exe to Log Off a User
Flags Windows executions of shutdown.exe with /l to log a user off.
frack113, Huntrule TeamWindowsprocess_creationMedium93Free2022-10-01Windows PDQ Deploy Console Execution
Alerts on Windows execution of PDQ Deploy Console (PDQDeployConsole.exe) based on process metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium261Free2022-10-01Windows RDP Registry Settings Modified to Zero
Alerts when RDP-related registry values are set to 0, potentially weakening remote access controls.
Samir Bousseaden, David ANDRE, Roberto Rodriguez @Cyb3rWard0g, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setMedium193Free2022-09-29Atlassian Bitbucket Command Injection Attempt via Archive API Parameters (Webserver)
Alerts on Bitbucket REST archive query parameters containing a %00--exec execution marker.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh92Free2022-09-29Windows: AnyDesk Password Piped via CMD Using --set-password
Alerts on Windows command lines that echo a value and set an AnyDesk password non-interactively via --set-password.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2022-09-28Windows IIS connection string decryption via aspnet_regiis -pdf
Flags aspnet_regiis.exe runs that target IIS connectionStrings for decryption using -pdf.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh144Free2022-09-28Windows: conhost.exe spawned by uncommon parent process
Alerts on conhost.exe launched by an uncommon parent process, using process creation parent image and command-line context.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium111Free2022-09-28PowerShell ScriptBlock Matching Invoke-Mimikatz Credential Dump Commands (Windows)
Detects PowerShell ScriptBlocks containing Mimikatz-like credential dump and certificate extraction command strings.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsps_scriptHigh112Free2022-09-28AnyDesk Windows: suspicious executable/DLL writes excluding gcapi.dll
Alerts when AnyDesk.exe or AnyDeskMSI.exe writes .dll/.exe files, excluding gcapi.dll.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh173Free2022-09-28