Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
59 rules
Cisco AAA Commands Indicating File Deletion on Local Flash Storage
Flags Cisco AAA log entries referencing flash file erase, delete, or format operations that may indicate stealthy cleanup.
Austin Clark, Huntrule TeamCiscoaaaMedium359Free2019-08-12Cisco AAA discovery via show/dir commands
Alerts on Cisco AAA log entries with discovery-oriented 'dir' and 'show' command keywords.
Austin Clark, Huntrule TeamCiscoaaaLow299Free2019-08-12Cisco IOS AAA Crypto PKI Export/Import Commands
Alerts on Cisco IOS AAA logs showing crypto PKI export of private keys or PKI import of certificates/trustpoints.
Austin Clark, Huntrule TeamCiscoaaaHigh305Free2019-08-12Cisco Network OS Log and Archive Clearing via “clear logging” Commands
Flags Cisco network OS attempts to clear logs or archives via AAA command text.
Austin Clark, Huntrule TeamCiscoaaaHigh234Free2019-08-12Cisco AAA configuration changes enabling SPAN/RSPAN monitoring capture
Alerts on Cisco AAA logs referencing SPAN/RSPAN or monitor capture point configuration changes.
Austin Clark, Huntrule TeamCiscoaaaMedium72Free2019-08-11Cisco AAA: Detection of 'show history' and 'show logging' command input
Alerts on Cisco AAA command input attempting to view history or logging via 'show history'/'show logging' commands.
Austin Clark, Huntrule TeamCiscoaaaMedium141Free2019-08-11Cisco IOS AAA Logging Disabled via 'no logging' and 'no aaa new-model' commands
Flags Cisco AAA command text that includes 'no logging' and/or 'no aaa new-model' to indicate logging being turned off.
Austin Clark, Huntrule TeamCiscoaaaHigh93Free2019-08-11Cisco AAA Command Output Collection: show running/startup-config and archive config
Detects Cisco command strings attempting to collect device configuration via show running/startup/archived config.
Austin Clark, Huntrule TeamCiscoaaaLow4010Free2019-08-11Firewall Rule Accepting Cleartext Protocol Ports
Alerts on firewall-allowed traffic to common service ports that may carry credentials over unencrypted channels.
Alexandr Yampolskyi, SOC Prime, Tim Shelton, Huntrule TeamNetworkfirewallLow62Free2019-03-26Zeek SMB spoolss Named Pipe (IPC$) Access
Flags Zeek SMB events accessing the spoolss named pipe via IPC$.
OTR (Open Threat Research), @neu5ron, Huntrule TeamZeeksmb_filesMedium298Free2018-11-28DNS TXT Answers Containing Command Execution Keywords (IEX, Invoke-Expression, cmd.exe)
Alerts on DNS TXT answers containing IEX/Invoke-Expression or cmd.exe strings indicative of execution-oriented payloads.
Markus Neis, Huntrule TeamNetworkdnsHigh133Free2018-08-08Suspicious DNS queries to api.telegram.org for Telegram Bot API traffic
Flags DNS queries to api.telegram.org that may indicate Telegram Bot API usage by bots or malware.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsMedium97Free2018-06-05Suspicious DNS Queries Containing Base64-Padding Pattern (==.)
Alerts on DNS queries containing the base64 delimiter pattern '==.' consistent with encoded data in DNS.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsMedium142Free2018-05-10Cobalt Strike-style DNS Beaconing Queries (DNS)
Flags DNS queries with Cobalt Strike-style stage subdomain patterns used for covert beaconing.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsCritical81Free2018-05-10