Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux auditd: BPFDoor .pid or .lock file access in /var/run
Alerts on auditd-monitored access to specific /var/run .pid and .lock files associated with BPFDoor-style behavior.
Rafal Piasecki, Huntrule TeamLinuxauditdHigh416Free2022-08-10Linux auditd: iptables NAT redirect execution to altered TCP destination ports
Flags iptables NAT REDIRECT commands with --to-ports values 42–43 observed via Linux auditd EXECVE.
Rafal Piasecki, Huntrule TeamLinuxauditdMedium141Free2022-08-10Azure Entra Audit Logs: Temporary Access Pass Method Added to an Account
Flags admin registration of a temporary access pass method in Azure audit logs for user accounts.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh3910Free2022-08-10Azure Entra: Guest User Invitation Failed When Initiated by Non-Privileged User
Identifies failed guest user invitations in Azure audit logs when the inviter lacks required permissions.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsMedium123Free2022-08-10Windows Registry Persistence via MyComputer \"Default\" Value Modification
Detects changes to Explorer\MyComputer (Default) registry value that can redirect a launched binary for persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh134Free2022-08-09Windows Persistence Attempt via ErrorHandler.cmd in C:\WINDOWS\Setup\Scripts\
Alerts on writing ErrorHandler.cmd to C:\WINDOWS\Setup\Scripts\, a persistence-relevant location on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium292Free2022-08-09Windows file creation for SharpHound/BloodHound collection output filenames
Flags SharpHound/BloodHound default collection export files (zip and multiple JSON datasets) from Windows file events.
C.J. May, Huntrule TeamWindowsfile_eventHigh111Free2022-08-09Azure Entra PIM Role Setting Changes in Audit Logs
Alerts on Azure PIM role setting update events recorded in audit logs.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh173Free2022-08-09Azure PIM Alert Setting Disabled (Audit Log Message Detection)
Flags Azure audit log events where PIM alerts are disabled (message: "Disable PIM Alert").
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh375Free2022-08-09Azure PIM Approval or Denial Recorded in Audit Logs
Flags Azure PIM elevation requests that are approved or denied in audit logs for investigation.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Huntrule TeamAzureauditlogsHigh164Free2022-08-09Windows SafeBoot Registry Key Deletion via reg.exe Command-Line
Flags reg.exe deleting the \SYSTEM\CurrentControlSet\Control\SafeBoot registry key via command line.
Nasreddine Bencherchali (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh123Free2022-08-08Windows mshta.exe launched with URL-based arguments (http/https/ftp)
Alerts when mshta.exe is executed with HTTP/HTTPS/FTP URLs in the command line, consistent with remote HTA execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh361Free2022-08-08Windows Registry Persistence: DbgManagedDebugger Debugger Value Added
Alerts on registry sets that add a Debugger value under DbgManagedDebugger, indicating potential crash-triggered persistence.
frack113, Huntrule TeamWindowsregistry_setMedium3810Free2022-08-07Windows Process Creation: Detect Use of 8.3 Short Name in Image Path (~1/~2)
Alerts on Windows process launches whose Image path contains 8.3 short-name markers (~1\ or ~2\), excluding several known benign parents.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium373Free2022-08-07Windows Process Creation: Command Line Uses 8.3 Short-Name Paths (~1 or ~2)
Alert on Windows command lines referencing 8.3 short paths (~1\, ~2\) that may indicate path obfuscation.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium70Free2022-08-07