Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows Registry: AllowAnonymousCallback Enabled for Anonymous Remote Connection
Alerts on setting AllowAnonymousCallback to 0x00000001 in the CIMOM key, enabling anonymous remote connections.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setMedium102Free2023-11-03Windows image load and execution of unsigned Thor scanner (thor.exe/thor64.exe)
Alerts on thor.exe/thor64.exe image loads on Windows where the Authenticode signature is missing or not from Nextron Systems.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh469Free2023-10-29Windows Process Creation: VS Code Tunnel (code-tunnel) Installed as a Service
Alerts on Windows process command lines consistent with installing VS Code tunnel (code-tunnel) as a service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2023-10-25Windows: VS Code Tunnel Launching PowerShell or WSL/Bash Shell
Flags VS Code tunnel (node.exe) spawning PowerShell, WSL, or bash shell processes on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2023-10-25Windows Process Creation: Visual Studio Code Tunnel (.exe tunnel) Execution
Flags cmd.exe-launched Visual Studio Code tunnel processes with expected tunnel and license-accept arguments on Windows.
Nasreddine Bencherchali (Nextron Systems), citron_ninja, Huntrule TeamWindowsprocess_creationMedium70Free2023-10-25Windows file creation of code_tunnel.json outside Code/VsCode executables
Alerts on creation of code_tunnel.json on Windows when it isn’t created by typical VS Code binaries.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh151Free2023-10-25Windows File Creation by VS Code Tunnel node.exe in .vscode-server History
Alerts on node.exe creating files under .vscode-server User History when the process runs from a VS Code server tunnel path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium152Free2023-10-25Windows DNS Queries to Visual Studio Code Tunnel Domains
Alerts on Windows DNS queries to .tunnels.api.visualstudio.com, matching Visual Studio Code tunnel endpoints.
citron_ninja, Huntrule TeamWindowsdns_queryMedium189Free2023-10-25Windows DNS Queries to Devtunnels .devtunnels.ms Domains
Alerts on Windows DNS queries for .devtunnels.ms domains, which may indicate DevTunnels-based C2 or persistence.
citron_ninja, Huntrule TeamWindowsdns_queryMedium112Free2023-10-25Windows Process Execution of findstr.EXE for Security Tool Keyword Filtering
Alerts on Windows findstr.exe executions that filter output using security software and antivirus-related keywords.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium202Free2023-10-20Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsfile_eventHigh378Free2023-10-19Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWindowsregistry_setLow132Free2023-10-18Windows Process Execution: curl.exe Downloading Files From an IP URL
Flags curl.exe commands that download via an IP-based URL using output/remote-name flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium383Free2023-10-18Windows CertOC.exe Downloads File From IP-Based URL Using -GetCACAPS
Flags CertOC.exe executions using an IP-based URL in the command line with -GetCACAPS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2023-10-18Windows Process Creation: CoercedPotato.exe Execution via ExploitId Parameters
Flags Windows process creation for CoercedPotato.exe with --exploitId and known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh253Free2023-10-11