Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,468 rules
Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh122Free2023-05-04Windows Non-Browser Process Network Connection to api.notion.com
Alerts when a non-browser Windows process connects to api.notion.com, excluding common browsers and the Notion desktop app.
Gavin Knapp, Huntrule TeamWindowsnetwork_connectionLow130Free2023-05-03Windows Suspicious Non-Browser Network Connections to Google API Endpoints
Alerts on suspicious Windows processes connecting to Google API hostnames, excluding common browsers and known benign apps.
Gavin Knapp, Huntrule TeamWindowsnetwork_connectionMedium478Free2023-05-01Windows Winlogon Outbound Network Connections to Public IPs
Flags outbound connections initiated by winlogon.exe to non-local public destination IPs on Windows.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamWindowsnetwork_connectionMedium101Free2023-04-28Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh386Free2023-04-27Windows Security: Security-Enabled Global Group Deletion (Event ID 4730/634)
Alerts on Windows Security audit events indicating a security-enabled global group was deleted.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow191Free2023-04-26Windows Security Log: Member Removed from Security-Enabled Global Group
Flags Windows Security Log events showing a member was removed from a security-enabled global group.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow162Free2023-04-26Windows Security: Member Added to Security-Enabled Global Group
Alerts when Windows logs show a user was added to a security-enabled global group via Event ID 4728 or 632.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow334Free2023-04-26Suspicious Windows Network Connections to External IP Lookup Service APIs
Alerts on non-browser outbound connections from Windows hosts to public IP lookup API domains.
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium456Free2023-04-24Windows PowerShell Invoke-WebRequest Execution via Direct IP in Command Line
Alerts when PowerShell executes web-request aliases targeting direct IP URLs, indicating possible remote content access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-04-21Windows Scheduled Task Creation with Schtasks -XML Using Non-.xml File
Alerts when schtasks.exe creates a scheduled task using -XML but the referenced file does not end with .xml.
Swachchhanda Shrawan Poudel, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium292Free2023-04-20Windows RDP client Mstsc.EXE launched from uncommon browser or email parent process
Alerts when mstsc.exe is spawned by a browser or Outlook, suggesting potential RDP access using a local .rdp file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2023-04-18Windows mstsc.exe launched with a local .rdp file from suspicious paths
Alerts on mstsc.exe executions that use a local .rdp file referenced from suspicious command-line paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-04-18Windows mstsc.exe launched with local .rdp file argument
Alerts on mstsc.exe executions that reference local .rdp files via the command line.
Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock, Huntrule TeamWindowsprocess_creationLow332Free2023-04-18Windows: Uncommon Process Creates .rdp Remote Desktop File
Alerts on creation of .rdp files by processes that are not typically associated with producing them on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-04-18