Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Linux Process Creation: crontab -l Enumeration
Flags Linux executions of /crontab with the -l option to list a user’s scheduled cron tasks.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationLow151Free2023-06-02Linux Shell Script Creation in /etc/profile.d/ for Persistence
Alerts on creation of .sh/.csh scripts in /etc/profile.d, a common place for persistence via shell startup.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxfile_eventLow143Free2023-06-02Windows Registry: New ODBC Driver Registration via ODBCINST.INI
Flags Windows registry changes that add ODBC driver entries under ODBCINST.INI, with exclusions for specific known benign cases.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow143Free2023-05-23Windows Excel Loads .XLL Add-In Files
Flags excel.exe loading a .XLL add-in module, an execution indicator for potential malicious add-in activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadLow110Free2023-05-12Windows file events matching SNAKE-related installer filename indicators
Flags Windows file events with target filenames ending in common SNAKE installer indicators like jpsetup.exe and jpinst.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow132Free2023-05-10Windows PowerShell Module File Creation via PowerShell Processes
Alert when PowerShell creates module-related files under WindowsPowerShell or PowerShell 7 module directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow152Free2023-05-09Windows PowerShell dropping a .ps1 script from powershell.exe or pwsh.exe
Alerts when PowerShell creates a dropped .ps1 script file on Windows, excluding common benign temp and test outputs.
frack113, Huntrule TeamWindowsfile_eventLow374Free2023-05-09Windows PowerShell Import-Module Cmdlet Execution
Flags PowerShell command lines containing Import-Module, indicating module loading into the current session.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-05-09Windows: File Creation of NTDS.DIT (Active Directory Database)
Flags creation of an ntds.dit file on Windows, an Active Directory database artifact often associated with credential access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow172Free2023-05-05Windows Non-Browser Process Network Connection to api.notion.com
Alerts when a non-browser Windows process connects to api.notion.com, excluding common browsers and the Notion desktop app.
Gavin Knapp, Huntrule TeamWindowsnetwork_connectionLow100Free2023-05-03Windows Security: Security-Enabled Global Group Deletion (Event ID 4730/634)
Alerts on Windows Security audit events indicating a security-enabled global group was deleted.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow171Free2023-04-26Windows Security Log: Member Removed from Security-Enabled Global Group
Flags Windows Security Log events showing a member was removed from a security-enabled global group.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow162Free2023-04-26Windows Security: Member Added to Security-Enabled Global Group
Alerts when Windows logs show a user was added to a security-enabled global group via Event ID 4728 or 632.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow334Free2023-04-26Windows mstsc.exe launched with local .rdp file argument
Alerts on mstsc.exe executions that reference local .rdp files via the command line.
Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock, Huntrule TeamWindowsprocess_creationLow332Free2023-04-18Windows winget AppInstaller admin_settings registry modification via winget.exe
Detects winget.exe-driven changes to AppInstaller admin_settings in the registry under LocalState\admin_settings.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow413Free2023-04-17