Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh465Free2023-05-05Windows Suspicious File Creation in C:\PerfLogs with Executable/Script Extensions
Alerts on creation of potentially malicious file types in C:\PerfLogs\ on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium151Free2023-05-05Windows: File Creation of NTDS.DIT (Active Directory Database)
Flags creation of an ntds.dit file on Windows, an Active Directory database artifact often associated with credential access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow172Free2023-05-05Windows Process: sqlcmd.exe Querying Veeam Backup Databases
Flags sqlcmd.exe command lines querying Veeam backup database objects associated with repository and credential data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium4310Free2023-05-04Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical415Free2023-05-04Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh122Free2023-05-04Windows Non-Browser Process Network Connection to api.notion.com
Alerts when a non-browser Windows process connects to api.notion.com, excluding common browsers and the Notion desktop app.
Gavin Knapp, Huntrule TeamWindowsnetwork_connectionLow130Free2023-05-03Windows Suspicious Non-Browser Network Connections to Google API Endpoints
Alerts on suspicious Windows processes connecting to Google API hostnames, excluding common browsers and known benign apps.
Gavin Knapp, Huntrule TeamWindowsnetwork_connectionMedium458Free2023-05-01Windows Winlogon Outbound Network Connections to Public IPs
Flags outbound connections initiated by winlogon.exe to non-local public destination IPs on Windows.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamWindowsnetwork_connectionMedium101Free2023-04-28Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh386Free2023-04-27Windows Security: Security-Enabled Global Group Deletion (Event ID 4730/634)
Alerts on Windows Security audit events indicating a security-enabled global group was deleted.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow171Free2023-04-26Windows Security Log: Member Removed from Security-Enabled Global Group
Flags Windows Security Log events showing a member was removed from a security-enabled global group.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow162Free2023-04-26Windows Security: Member Added to Security-Enabled Global Group
Alerts when Windows logs show a user was added to a security-enabled global group via Event ID 4728 or 632.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow334Free2023-04-26Suspicious Windows Network Connections to External IP Lookup Service APIs
Alerts on non-browser outbound connections from Windows hosts to public IP lookup API domains.
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium456Free2023-04-24Windows PowerShell Invoke-WebRequest Execution via Direct IP in Command Line
Alerts when PowerShell executes web-request aliases targeting direct IP URLs, indicating possible remote content access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-04-21