Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Persistence: Outlook LoadMacroProviderOnBoot Registry Setting Modification
Alerts on enabling the Outlook LoadMacroProviderOnBoot registry setting, which can allow automatic VBA module loading at startup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh348Free2021-04-05Windows: New Outlook VBAProject OTM Macro File Created
Flags Windows file creation of Outlook VBAProject.OTM when initiated by outlook.exe.
"@ScoubiMtl, Huntrule Team"Windowsfile_eventMedium102Free2021-04-05Windows Exchange Management: Set-OabVirtualDirectory ExternalUrl to script content
Detects Exchange Management changes to OAB ExternalUrl containing script indicators and Page_Load.
Jose Rodriguez @Cyb3rPandaH, Huntrule TeamWindowsmsexchange-managementHigh296Free2021-03-15Windows schtasks.exe Creating One-Time Scheduled Tasks Using Temp Folder
Alerts on schtasks.exe commands that create one-time scheduled tasks referencing a Temp directory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh449Free2021-03-11Windows: Suspicious Service Binary Executed from Public/System Directories
Alerts on service-hosted processes executing from user/public or system-writable directories on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2021-03-09Windows Registry: VBScript/HTMLApplication Payload Stored Under Run Keys
Flags registry persistence where script payload indicators like vbscript: and RunHTMLApplication appear in set registry values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh235Free2021-03-05Windows Process Creation: rundll32.exe Command Line Invoking .sys Files
Flags Windows rundll32.exe executions whose command line references .sys file patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2021-03-05Windows rundll32 Executing Inline VBScript via RegRead
Detects rundll32.exe command lines containing inline VBScript execution with RegRead and window.close.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh398Free2021-03-05Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Flags PowerShell executions that Add-PSSnapin Exchange snap-ins, consistent with Exchange mailbox/config data collection.
FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh326Free2021-03-03Windows PowerShell TcpClient reverse-shell connection attempt via Net.Sockets
Alerts on PowerShell processes launching with .NET TcpClient stream/write patterns consistent with reverse TCP connectivity.
FPT.EagleEye, wagga, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-03-03Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical153Free2021-02-26Windows Process Creation: finger.exe Execution
Alerts on Windows executions of finger.exe, a legacy utility that may indicate suspicious reconnaissance or network activity.
Florian Roth (Nextron Systems), omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh143Free2021-02-24Windows ScreenConnect Installation Execution via Remote Access Parameters
Flags Windows executions of ScreenConnect with remote access command-line parameters indicating remote session setup.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2021-02-11Windows Process Creation: logman.exe Used to Stop or Delete ETW Trace Sessions
Alerts when logman.exe is used to stop or delete Windows ETW trace sessions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2410Free2021-02-11Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Detects AdFind executions on Windows that include common AD reconnaissance parameters.
Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2021-02-02