Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Service Created by Client With PID 0 or Parent PID 0
Alerts on Windows service installs (EID 4697) where the client or parent PID is 0.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh162Free2022-09-15Linux Suspicious curl Start with User-Agent Modification Flags
Flags Linux curl invocations that set a custom User-Agent using -A/--user-agent.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium247Free2022-09-15Linux: Suspicious curl upload via form or data flags
Alerts on Linux curl executions that include file upload or form submission flags in their command line, excluding localhost targets.
Nasreddine Bencherchali (Nextron Systems), Cedric MAURUGEON (Update), Huntrule TeamLinuxprocess_creationMedium151Free2022-09-15Linux Service Management Command Usage to Stop or Disable Services
Flags Linux service-control commands with stop/disable intent, while excluding selected benign upgrade and snap workflows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium168Free2022-09-15Process Creation: curl on Linux
Flags Linux process starts for the curl binary, indicating potential remote file download or web requests.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow90Free2022-09-15Linux crontab Removal via "crontab -r" Process Command Line
Identifies attempts to remove the current user crontab via "crontab -r" on Linux.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium104Free2022-09-15Linux: chattr Used to Remove Immutable File Attribute
Flags Linux process use of chattr with -i to remove the immutable file attribute.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium121Free2022-09-15Linux: Base64-Encoded Shebang Patterns in Command Line
Flags Linux command lines containing Base64-encoded shebang prefixes for common shells, indicating potential encoded script execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium163Free2022-09-15Windows CLI Processes Using Common Weak or Abused Passwords
Alerts when Windows command lines include common weak or reused password values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium136Free2022-09-14Windows PowerShell Disables Windows Firewall Profiles via Set-NetFirewallProfile
Flags PowerShell commands attempting to turn off Windows Firewall profiles using Set-NetFirewallProfile.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium172Free2022-09-14Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2022-09-14Windows UAC Bypass via Elevated COM interface using ICMLuaUtil
Flags dllhost.exe parent launches tied to elevated COM /Processid GUIDs consistent with UAC bypass behavior on Windows.
Florian Roth (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-13Windows: Taskkill used to terminate ccSvcHst.exe (Symantec Endpoint Protection service impairment)
Flags Windows taskkill /F /IM ccSvcHst.exe executions that can disable Symantec Endpoint Protection services.
Ilya Krestinichev, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh381Free2022-09-13Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution
Flags Windows executions of chisel.exe with client/server tunneling and SOCKS5 reverse arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-09-13Windows Process Creation: 3proxy Proxy Server Execution
Detects execution of 3proxy.exe with local 127.0.0.1 proxy binding on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2022-09-13