Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
Tim Rauch, frack113, Huntrule TeamWindowsps_scriptHigh204Free2022-09-20Windows Process Creation: Remote Utilities renamed to rutserv.exe or rfusclient.exe
Alerts on suspicious Windows execution tied to "Remote Utilities" where the image does not match known rutserv.exe/rfusclient.exe names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2022-09-19Windows: Detects NetSupport RAT client32.exe execution using Imphash and filename metadata
Flags renamed NetSupport RAT client32.exe launches on Windows using a specific Imphash and file metadata, while filtering a matching image path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-09-19Windows: RURAT (Remote Utilities) Executed From Unusual Path
Alerts on Remote Utilities RURAT executables running outside the typical Program Files install paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium211Free2022-09-19Windows: NetSupport client32.exe Executed From Non-Standard Directory
Flags NetSupport client32.exe launched from locations outside Program Files on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium132Free2022-09-19Windows: Detect winPEAS privilege escalation reconnaissance execution
Flags Windows executions of winPEAS/PEASS-ng based on image name and command-line discovery options and release download indicators.
Georg Lauenstein (sure[secure]), Huntrule TeamWindowsprocess_creationHigh408Free2022-09-19Windows Registry: Tampering ChannelAccess Permissions for WINEVT Event Channels
Alerts on registry updates to WINEVT ChannelAccess that set SDDL permissions granting elevated access to event channels.
frack113, Huntrule TeamWindowsregistry_setHigh322Free2022-09-17Windows Process Creation: Command Line Targets Microsoft Teams Cookies or LevelDB
Alerts when non-Teams processes reference Microsoft Teams Cookies or Local Storage leveldb paths in their command line.
"@SerkinValery, Huntrule Team"Windowsprocess_creationMedium151Free2022-09-16PowerShell Adds Windows Defender Exclusions via Add-MpPreference/Set-MpPreference
Flags PowerShell commands that add Windows Defender exclusions using Add-MpPreference/Set-MpPreference with exclusion parameters.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsps_scriptMedium415Free2022-09-16Windows PowerShell Sensitive File Discovery via ScriptBlock Enumeration
PowerShell script blocks using recursive file enumeration that target sensitive file extensions.
frack113, Huntrule TeamWindowsps_scriptMedium2310Free2022-09-16Windows IIS WebServer Access Log Files Deleted
Alerts when IIS access log files (.log) under inetpub\logs\LogFiles\ are deleted.
Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium449Free2022-09-16Windows Security 4663: Access to Microsoft Teams token and local storage files
Identifies non-Teams.exe processes accessing Microsoft Teams cookies or local storage objects on Windows (Event 4663).
"@SerkinValery, Huntrule Team"WindowssecurityHigh121Free2022-09-16Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Detects SharPersist execution on Windows via process name and persistence-related command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh156Free2022-09-15Windows: Service Created by System Using Client with PID 0 (SCM Event 7045)
Alerts on Windows service installation events (SCM EventID 7045) where the client process ID is 0.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowssystemHigh391Free2022-09-15