Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Azure AD: Detect Removal From Group With Conditional Access Policy Modification Rights
Alerts when a user is removed from a group that can modify Conditional Access policies in Azure Entra.
Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner', Huntrule TeamAzureauditlogsMedium101Free2022-08-04Azure Entra: Added member to group granting Conditional Access policy modification
Alerts when a user is added to a group that can modify Conditional Access policies in Azure Entra ID.
Mark Morowczynski '@markmorow', Thomas Detzner '@tdetzner', Huntrule TeamAzureauditlogsMedium102Free2022-08-04Windows: Detect wusa.exe Cab Extraction Using /extract
Flags wusa.exe running with /extract:, a behavior consistent with CAB extraction and potential payload staging.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2022-08-04Windows CLI usage of obfuscated IP address patterns in ping/arp commands
Alerts when ping or arp command lines include obfuscated/encoded IP address indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-08-03Windows Process Creation: Obfuscated IP Address in Download Command URLs
Alerts on Windows download commands that include obfuscated/encoded IP addresses in the URL.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-08-03Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical407Free2022-08-03Windows Security Mitigations: Unsigned DLL Blocked from User-Writable Paths
Alerts on blocked unsigned DLL loads targeting public, downloads, desktop, or temp directories in Windows Security Mitigations logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurity-mitigationsHigh132Free2022-08-03Windows Security: DiagTrackEoP POC Default UserName Login Attempt (LogonType 9)
Alerts on Windows 4624 LogonType 9 events targeting a known DiagTrackEoP default username.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityCritical120Free2022-08-03Azure AD audit logs: Successful user-initiated password reset
Alerts on successful Azure AD password reset events initiated by a user account.
YochanaHenderson, '@Yochana-H', Huntrule TeamAzureauditlogsMedium121Free2022-08-03Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2210Free2022-08-02Windows PowerShell Invoke-WebRequest Download to Suspicious Paths
Alert when PowerShell uses Invoke-WebRequest/aliases with download flags and targets suspicious file locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-08-02Windows: Detect VMwareXferlogs.exe Executed from Non-default Path
Alert on VMwareXferlogs.exe launching from an unexpected directory, a potential DLL sideloading technique on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh125Free2022-08-02Windows mpclient.dll Sideloading via MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when mpclient.dll is loaded by MpCmdRun.exe or NisSrv.exe outside known Windows Defender directories.
Bhabesh Raj, Huntrule TeamWindowsimage_loadHigh82Free2022-08-02Windows: Potential DLL sideloading via VMwareXferlogs loading glib-2.0.dll from non-standard path
Alerts on VMwareXferlogs.exe loading glib-2.0.dll from outside the default VMware directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh2810Free2022-08-02Windows Code Integrity blocks unsigned DLL loads into MpCmdRun.exe and NisSrv.exe
Flags security-mitigations events where MpCmdRun or NisSrv are prevented from loading unsigned DLLs.
Bhabesh Raj, Huntrule TeamWindowssecurity-mitigationsHigh91Free2022-08-02