Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,331 rules
Azure Entra ID Identity Protection Unlikely Travel Risk Events
Alerts on unlikelyTravel risk events tied to geographically distant sign-ins and potential deviation from user travel history.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh162Free2023-09-03Azure RiskDetection flags riskyIPAddress from anonymous proxy IP addresses
Alerts when Azure reports user activity linked to a risky anonymous proxy IP address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh2410Free2023-09-03Azure Entra ID anomalous user activity risk event
Alerts on Azure AD risk events indicating anomalous user activity via riskEventType=anomalousUserActivity.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh121Free2023-09-03Qakbot Uninstaller Execution via QbotUninstall.exe (Windows Process Creation)
Alerts on execution of the QbotUninstall.exe uninstaller when it matches known Qakbot uninstaller hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-08-31Suspicious rundll32 Single-Digit DLL Execution with DllRegisterServer on Windows
Flags rundll32.exe running 1.dll with DllRegisterServer, a pattern seen in suspicious DLL execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2023-08-31Suspicious WinRAR Child Process Execution Attempt on Windows (CVE-2023-38331)
Alerts on WinRAR spawning command/scripting child processes tied to Temp\Rar$ activity consistent with CVE-2023-38331 exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationHigh162Free2023-08-30Windows: WinRAR double-extension file creation with space in Temp Rar$ path
Alerts on WinRAR-created Temp Rar$ files with double extensions separated by a space on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh357Free2023-08-30Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2023-08-29Windows: Local User Creation via net.exe with DarkGate and SafeMode
Alerts on net.exe adding a local user when the command line includes “DarkGate” and “SafeMode”.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2023-08-27Windows Fake wermgr.exe Execution via Renamed cmd/powershell/powershell_ise
Detects disguised execution of cmd or PowerShell by matching original file name with a wermgr.exe process image.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-08-23Windows File Creation of wermgr.exe in Uncommon Directory (Potential CVE-2023-36874)
Alerts on wermgr.exe creation in atypical Windows directories that may indicate filename spoofing.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh161Free2023-08-23Windows Process Watch: PythonFunctionWarnings Disabled via Excel Security Registry Setting
Flags Excel-related process command lines that disable Python function execution warnings via PythonFunctionWarnings=0.
"@Kostastsale, Huntrule Team"Windowsprocess_creationHigh411Free2023-08-22Azure Entra ID Riskdetection: Anonymous IP Address sign-in risk events
Detects Azure sign-in risk events labeled as anonymized/anonymous IP addresses.
Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh82Free2023-08-22Suspicious Child Process Creation from BgInfo.EXE on Windows
Alerts when BgInfo.exe spawns suspicious calc/cmd/cscript/mshta/powershell/wscript or runs from common AppData/Temp paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2023-08-16Suspicious aspnet_compiler.exe Execution from User or Temp Paths on Windows
Alerts when aspnet_compiler.exe runs with command lines indicating user-writable or temp/task paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh192Free2023-08-14