Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
PowerShell Net.WebClient DownloadFile/DownloadString Usage (Classic)
Flags PowerShell Classic commands using Net.WebClient to download content via DownloadFile or DownloadString.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_classic_startLow233Free2017-03-05Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Flags Service Control Manager service creation with ImagePath names tied to credential dumping tools (Event ID 7045).
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssystemHigh121Free2017-03-05Windows Security EID 4697 Service Execution of Credential Dumping Tools
Alerts on Event ID 4697 service execution paths containing common credential dumping tool names on Windows.
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssecurityHigh422Free2017-03-05Windows: Detects Access to ADMIN$ Network Share (Event 5140)
Alerts on Windows Security event 5140 entries where an access request targets the ADMIN$ share.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityLow104Free2017-03-04Windows LSASS Remote Thread Creation Indicative of Password Dumping
Flags Windows remote thread creation targeting lsass.exe, a common pattern in password dumping activity.
Thomas Patzke, Huntrule TeamWindowscreate_remote_threadHigh427Free2017-02-19Windows Security: Suspicious Failed Logons Using Uncommon Status/Substatus Codes
Alerts on Windows failed logons (4625/4776) with specific restricted-status codes indicating potential account tampering or access probing.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium103Free2017-02-19Windows Security Event 4794 Password Change for DSRM Account
Flags potential changes to the DSRM administrator password on Windows domain controllers using Security EventID 4794.
Thomas Patzke, Huntrule TeamWindowssecurityHigh92Free2017-02-19Windows Security Events: SID History Added to Active Directory Object
Flags Windows Security events indicating Active Directory SIDHistory changes that can grant additional privileges.
Thomas Patzke, @atc_project (improvements), Huntrule TeamWindowssecurityMedium409Free2017-02-19Windows Application Logs: Match Antivirus Signature and Malware Keyword Hits
Alerts on Windows application log lines containing known AV signatures and malware keywords, excluding some anti-ransomware/keygen/crack terms.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule TeamWindowsapplicationHigh63Free2017-02-19Windows Driver Load from Temporary Directory Paths
Detects Windows driver loads whose ImageLoaded path contains the temporary directory (\Temp\).
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh3610Free2017-02-12Windows Security: Detect LSASS handle access for SAM_DOMAIN (0x705)
Flags handle opens to lsass.exe with access mask 0x705 targeting SAM_DOMAIN, indicative of credential dumping.
sigma, Huntrule TeamWindowssecurityHigh102Free2017-02-12Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Alerts on Windows Security failures for Kerberos TGT-related operations using specific Kerberos event IDs and status codes.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh271Free2017-02-10Windows Kerberos Service Tickets Requesting RC4 Encryption (EventID 4769)
Flags Windows Kerberos service ticket requests using RC4 encryption while excluding '$' machine/service accounts.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium275Free2017-02-06Windows Event Logs: Mimikatz Keyword Indicators
Detects Mimikatz-related keywords in Windows event logs while filtering Sysmon EventID 15 to limit noise.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindows—High427Free2017-01-10Windows Event Log Cleared (Microsoft-Windows-Eventlog EventID 104)
Alerts when Windows event logs are cleared, based on Microsoft-Windows-Eventlog Event ID 104 from System telemetry.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemMedium181Free2017-01-10