Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Command Lines Indicating ngrok.exe Tunnel Setup
Detects Windows executions of ngrok.exe with TCP/HTTP tunneling and authtoken/start-all YAML configuration patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh261Free2021-05-14Windows: Detect Rclone command execution with exfiltration-oriented flags
Identifies likely rclone.exe exfiltration activity on Windows by matching command-line flags and rclone executable characteristics.
Bhabesh Raj, Sittikorn S, Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsprocess_creationHigh183Free2021-05-10Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.
Bhabesh Raj, Huntrule TeamWindowssystemCritical3010Free2021-05-06Windows whoami.exe Privilege Enumeration Using /priv Flag
Alerts on whoami.exe runs with /priv or -priv to enumerate current user privileges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2021-05-05Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh436Free2021-05-03Windows Security: Hidden Local User Account Creation (Event ID 4720)
Alerts on Windows 4720 local user creation for hidden accounts (username ending with '$'), excluding 'HomeGroupUser$'.
Christian Burkard (Nextron Systems), Huntrule TeamWindowssecurityHigh110Free2021-05-03Windows Process Access to svchost.exe with Credential Dumping Access Rights
Alerts on attempts to read svchost.exe memory consistent with credential dumping, excluding known benign callers.
Florent Labouyrie, Huntrule TeamWindowsprocess_accessHigh353Free2021-04-30PowerShell Defender Exclusion via Set/Add-MpPreference Command-Line Flags (Windows)
Detects PowerShell commands that add or set Microsoft Defender exclusions using Add/Set-MpPreference parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium316Free2021-04-29Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh497Free2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh142Free2021-04-23PowerShell ScriptBlock Certificate Export via Export-PfxCertificate or Export-Certificate
Detects PowerShell script blocks invoking certificate export cmdlets, which may be abused to steal sensitive certificate material.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptMedium111Free2021-04-23Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Flags HybridConnectionManager-initiated DNS queries to servicebus.windows.net on Windows.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsdns_queryHigh146Free2021-04-12Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Flags Windows Hybrid Connection Manager-related events mentioning sb:// and servicebus.windows.net.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsmicrosoft-servicebus-clientHigh82Free2021-04-12Windows Security Event 4697: HybridConnectionManager Service Installation
Alerts on HybridConnectionManager service installation on Windows via Security Event ID 4697.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh3310Free2021-04-12Windows Registry: Outlook Macro Security Level Set to Enable All Macros
Detects Outlook macro warning bypass by setting the Outlook security level registry value to enable all macros.
"@ScoubiMtl, Huntrule Team"Windowsregistry_setHigh101Free2021-04-05