Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows Security: Detect WRITE_DAC on AD DS objects (Event ID 4662)
Flags AD DS Security Event 4662 activity indicating WRITE_DAC permission changes on domain objects.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical101Free2019-09-12Windows Process Creation: Empire PowerShell UAC Bypass CommandLine Pattern
Flags Windows process creation events running Empire-style PowerShell UAC bypass command fragments.
Ecco, Huntrule TeamWindowsprocess_creationCritical61Free2019-08-30Windows Security: AD object replication attempted by non-machine account (Event ID 4662)
Alerts on AD replication-related object access events where the requester is not a machine account.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical103Free2019-07-26Windows Registry: Create/Modify CLSID/AppX keys associated with OceanLotus decoy paths
OceanLotus Registry Activity
megan201296, Jonhnathan Ribeiro, Huntrule TeamWindowsregistry_eventCritical121Free2019-04-14Windows Process CommandLine contains -export dll_u (DLL export function load)
Flags Windows processes that invoke a DLL export function named dll_u via command-line export arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical188Free2019-03-04Windows process activity matching WannaCry executables and ransom note text
Alerts on Windows process creation where WannaCry-related executables and the @Please_Read_Me@.txt command indicator appear.
Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationCritical428Free2019-01-16Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution
Flags Windows process execution indicative of NotPetya: clearing event logs with wevtutil and deleting C drive USN journal with fsutil.
Florian Roth (Nextron Systems), Tom Ueltschi, Huntrule TeamWindowsprocess_creationCritical113Free2019-01-16Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools
Alerts on suspicious svchost.exe or regsvr32.exe process executions with matching command-line and parent/child patterns indicative of Dridex activity.
Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical368Free2019-01-10Windows Process Creation: SecurityXploded PasswordDump.exe Execution
Alerts on Windows executions of SecurityXploded PasswordDump.exe based on process metadata and filename.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical382Free2018-12-19Windows Process Creation: Rubeus HackTool Execution Indicators
Flags Windows process executions of Rubeus.exe when command lines include Kerberos attack-related actions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical146Free2018-12-19Windows Service Control Manager: WerFaultSvc Installed via Service Creation (Event ID 7045)
Alerts on Windows Event 7045 service creation for "WerFaultSvc" as an indicator of dropper-style persistence.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemCritical373Free2018-11-23Windows Process Creation—CommandLine Indicators for APT29 2018 Phishing Campaign
Alerts on Windows command-line substrings seen in the 2018 APT29 phishing campaign indicators.
Florian Roth (Nextron Systems), @41thexplorer, Huntrule TeamWindowsprocess_creationCritical83Free2018-11-20Windows File Events: Detect ds7002*.lnk, .pdf, and .zip Indicators
Flags Windows file events with target filenames containing ds7002.lnk, ds7002.pdf, or ds7002.zip.
"@41thexplorer, Huntrule Team"Windowsfile_eventCritical101Free2018-11-20Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Triggers on AV signatures matching PWS* or known credential-dumping tool strings indicating potential password theft activity.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical93Free2018-09-09Antivirus signature match for exploitation framework indicators
Alerts when AV signature names contain indicators tied to exploitation frameworks and related backdoors.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical201Free2018-09-09