Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows: Detect MODE.COM Changing Code Page Settings
Detects MODE.COM executions that include code page selection parameters.
Nasreddine Bencherchali (Nextron Systems), Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationLow80Free2024-01-19macOS SIP Status Enumeration via csrutil status
Flags execution of "csrutil status" on macOS to enumerate System Integrity Protection state.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamMacosprocess_creationLow92Free2024-01-02Windows: tar.exe Archive Extraction Using -x Flag
Flags Windows process executions of tar.exe with -x to extract compressed archives.
AdmU3, Huntrule TeamWindowsprocess_creationLow339Free2023-12-19Windows tar.exe Used to Create Compressed Archives
Flags tar.exe (or bsdtar) command lines using -c/-r/-u to create or update compressed archives on Windows.
Nasreddine Bencherchali (Nextron Systems), AdmU3, Huntrule TeamWindowsprocess_creationLow103Free2023-12-19Windows WMIC System Information Discovery via WMI Command-Line Queries
Flags WMIC command-line queries that pull OS, hardware, disk, memory, BIOS, and GPU details while excluding VMware Tools discovery scripts.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationLow120Free2023-12-19Windows ImageLoad: Uncommon Process Loads RstrtMgr.dll (Restart Manager)
Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.
Luc Génaux, Huntrule TeamWindowsimage_loadLow141Free2023-11-28Okta: Access to /reports/password-health endpoint outside expected Admin Console use
Flags requests to Okta Password Health report endpoints (/reports/password-health/*) for threat hunting.
Muhammad Faisal (@faisalusuf), Huntrule TeamOktaoktaLow70Free2023-10-25Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWindowsregistry_setLow132Free2023-10-18Windows MSSQL Failed Logon (Event ID 18456) Detection
Alerts on MSSQL-related failed login attempts (Event ID 18456) captured in Windows application logs.
Nasreddine Bencherchali (Nextron Systems), j4son, Huntrule TeamWindowsapplicationLow80Free2023-10-11Windows ScreenConnect RMM System Command Execution via cmd.exe
Flags cmd.exe launched by ScreenConnect.ClientService.exe with a TEMP\ScreenConnect command-line path.
Ali Alwashali, Huntrule TeamWindowsprocess_creationLow131Free2023-10-10Windows: ScreenConnect Temporary File Creation in ConnectWiseControl Temp
Flags file writes to ScreenConnect’s ConnectWiseControl\Temp staging directory from ScreenConnect.WindowsClient.exe.
Ali Alwashali, Huntrule TeamWindowsfile_eventLow82Free2023-10-10Windows Application: ScreenConnect RMM File Transfer Activity (Event 201)
Flags ScreenConnect RMM file transfer events on Windows based on provider name, Event ID 201, and transfer action text.
Ali Alwashali, Huntrule TeamWindowsapplicationLow164Free2023-10-10Windows ScreenConnect Remote Command Execution (EventID 200)
Detects ScreenConnect command execution on Windows by matching EventID 200 with an 'Executed command of length' message.
Ali Alwashali, Huntrule TeamWindowsapplicationLow133Free2023-10-10Windows Service Registry Key ReadControl Access (Event ID 4663)
Flags READ_CONTROL access requests to service registry keys (\SYSTEM\ControlSet\Services\) via Windows Security Event 4663.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowssecurityLow153Free2023-09-28Windows Registry Scheduled Task Cache Key Creation Detection
Flags registry event activity under Scheduled TaskCache indicating scheduled task creation or updates on Windows.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowsregistry_eventLow80Free2023-09-27