Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
Windows DHCP Server Loaded Callout DLL via Registry
Flags DHCP Server events where a registry-specified callout DLL is loaded (Event ID 1033), indicating potential persistence or execution.
Dimitrios Slamaris, Huntrule TeamWindowssystemHigh81Free2017-05-15Windows Backup Catalog Deleted (Microsoft-Windows-Backup Event ID 524)
Alerts when Windows deletes the backup catalog via Microsoft-Windows-Backup Event ID 524.
Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), Huntrule TeamWindowsapplicationMedium152Free2017-05-12Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll
Alerts on WER EventID 1001 crashes where MsMpEng.exe and mpengine.dll appear in the event data.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh91Free2017-05-09Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll
Alerts on Windows Application Error EventID 1000 indicating a crash involving MsMpEng.exe and mpengine.dll.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh143Free2017-05-09Windows DNS ServerLevelPluginDll Registry Installation
Detects registry changes setting DNS ServerLevelPluginDll, which can enable malicious DNS plugin DLL loading after restart.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh365Free2017-05-08Windows: Detect dnscmd.exe setting ServerLevelPluginDll to install DNS plugin DLL
Flags dnscmd.exe DNS configuration that sets ServerLevelPluginDll, indicating potential malicious DNS server code injection.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh83Free2017-05-08Windows DNS Server error when loading ServerLevelPlugin DLL fails
Flags Windows DNS Server errors where the ServerLevelPluginDLL plugin DLL fails to load.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns-serverHigh351Free2017-05-08Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-04-15Windows Security: AD user/computer backdoor via msDS-AllowedToDelegateTo and delegation attributes
Alerts on AD delegation-related attribute changes that may create credentialless account control paths.
"@neu5ron, Huntrule Team"WindowssecurityHigh198Free2017-04-13PowerShell Credential Prompt via PromptForCredential
Flags PowerShell scripts that reference "PromptForCredential", indicating credential prompt behavior in Script Block Logging.
John Lambert (idea), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh389Free2017-04-09PowerShell downgrade indicators via EngineVersion=2. and HostVersion !=2. (Windows)
Detects PowerShell version mismatches that may indicate a downgrade attempt using EngineVersion vs HostVersion telemetry.
Florian Roth (Nextron Systems), Lee Holmes (idea), Harish Segar (improvements), Huntrule TeamWindowsps_classic_startMedium398Free2017-03-22Windows Registry UAC Bypass via Event Viewer Command Key (mscfile shell open command)
Alerts on registry changes to the mscfile shell open command key consistent with an Event Viewer UAC bypass technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh131Free2017-03-19Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-03-19Windows Network Connections to Uncommon Ports (8080, 8888)
Flags Windows-initiated connections to ports 8080/8888 excluding private/local IPs and Program Files binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium147Free2017-03-19Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh83Free2017-03-19