Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Uncommon Outbound Kerberos Traffic on Port 88
Alerts on initiated outbound connections to Kerberos TCP/88 from unexpected Windows processes.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowsnetwork_connectionMedium199Free2019-10-24Windows PowerShell Profile File Creation or Modification
Alerts on creation or modification of PowerShell profile.ps1 files in typical Windows and PowerShell 7 locations.
HieuTT35, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium153Free2019-10-24Windows Service Control Manager TAP Driver Installation (tap0901)
Flags Windows service installation events for TAP driver image paths containing 'tap0901'.
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowssystemMedium82Free2019-10-24Windows Security 4673: Failed LsaRegisterLogonProcess Handle Registration
Alerts on failed attempts to call LsaRegisterLogonProcess() in Windows Security (Event 4673), tied to the SeTcbPrivilege requirement.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh154Free2019-10-24Windows Security 4697: TAP Driver Service Installation (tap0901)
Alerts on Windows Security EID 4697 service installation events for TAP driver files containing "tap0901."
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowssecurityLow133Free2019-10-24Uncommon Outbound Kerberos Port 88 Network Connections (Windows Security Event 5156)
Alerts on rare outbound Kerberos (port 88) connections from non-browser/non-lsass processes using Windows Event 5156.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowssecurityMedium3110Free2019-10-24Windows Security 4611: Rubeus-Indicative New Trusted Logon Process Registration
Alerts on Windows Security Event 4611 registering a new trusted logon process named 'User32LogonProcesss'.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh141Free2019-10-24Windows Registry COM Hijacking via TreatAs Subkey in CLSID
Alerts on registry modifications to HKU\Classes\CLSID\*\TreatAs that may indicate COM object hijacking/persistence.
Kutepov Anton, oscd.community, Huntrule TeamWindowsregistry_setMedium225Free2019-10-23Windows: Sysmon filter driver unloaded using fltMC.exe
Identifies fltMC.exe commands attempting to unload the Sysmon filter driver via “unload sysmon”.
Kirill Kiryanov, oscd.community, Huntrule TeamWindowsprocess_creationHigh407Free2019-10-23Windows Raw Disk Access by Uncommon Process Paths
Alerts on Windows raw disk access by processes from uncommon or suspicious locations.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsraw_access_threadLow51Free2019-10-22Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh91Free2019-10-22Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationMedium325Free2019-10-22Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Flags reg.exe command lines exporting or saving HKLM registry hives tied to SAM, SYSTEM, and SECURITY.
Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh3510Free2019-10-22Windows Process Execution Matching SILENTTRINITY Stager Metadata (st2stager)
Flags Windows process creation events containing "st2stager" in PE metadata, indicating SILENTTRINITY stager activity.
Aleksey Potapov, oscd.community, Huntrule TeamWindowsprocess_creationHigh169Free2019-10-22Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Flags Windows processes whose command lines contain Mimikatz names and credential-dumping module/function arguments.
Teymur Kheirkhabarov, oscd.community, David ANDRE (additional keywords), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh123Free2019-10-22