Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell: DSInternals Get-ADReplAccount Enumeration
Alerts on PowerShell execution of Get-ADReplAccount with -All and -Server parameters for AD replication account enumeration.
frack113, Huntrule TeamWindowsps_scriptMedium172Free2022-02-06Windows Registry ServiceDll Hijack via Service Parameters\ServiceDll
Alerts on ServiceDll value changes for Windows services in the registry, indicating potential DLL load persistence.
frack113, Huntrule TeamWindowsregistry_setMedium141Free2022-02-04Windows: attrib.exe Executed with +s to Mark Files as System Files
Flags attrib.exe executions that include the +s switch to mark target files as system files.
frack113, Huntrule TeamWindowsprocess_creationLow60Free2022-02-04Linux auditd: systemd service file creation under systemd directories
Identifies new systemd unit file creation events under common systemd directories using auditd PATH create logs.
Pawel Mazur, Huntrule TeamLinuxauditdMedium133Free2022-02-03Windows NTLM brute force targeting workstation/device names
Alerts on NTLM EventID 8004 when WorkstationName equals common spoofed client names used in brute force attempts.
Jerry Shockley '@jsh0x', Huntrule TeamWindowsntlmMedium365Free2022-02-02Windows PowerShell: Suspicious Unblock-File to Remove Zone.Identifier
Flags PowerShell use of Unblock-File (-Path) that can remove Zone.Identifier downloaded-file metadata.
frack113, Huntrule TeamWindowsps_scriptMedium4510Free2022-02-01PowerShell Mount-DiskImage with -ImagePath to Access Disk Images
Alerts on PowerShell script blocks calling Mount-DiskImage with -ImagePath, indicative of disk-image-based payload staging.
frack113, Huntrule TeamWindowsps_scriptLow322Free2022-02-01Windows PowerShell: Suspicious Invoke-Item After Mount-DiskImage
Flags PowerShell that mounts an image, derives a drive letter, then runs content via invoke-item from that mount.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2022-02-01Windows Suspicious takeown.exe Recursive Ownership Change
Alerts when takeown.exe is run with recursive and file/folder targeting, indicating potential defense impairment via ownership changes.
frack113, Huntrule TeamWindowsprocess_creationMedium4610Free2022-01-30Windows PowerShell ScriptBlock Accessing Browser 'Login Data' Files
Flags PowerShell Copy-Item operations targeting browser Login Data credential database paths on Windows.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2022-01-30Windows File Writes of TeamViewer Session Logs
Flags Windows file creation events for TeamViewer session log artifacts like vprint.db and TVNetwork.log.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventMedium285Free2022-01-30Windows DNS Queries for TeamViewer Domains Triggered by Non-TeamViewer Image
Alerts when TeamViewer domains are resolved via DNS by a process whose image name does not include "TeamViewer".
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryMedium454Free2022-01-30Windows: Application Uninstall via WMIC.exe (WMIC call uninstall)
Flags WMIC.exe commands that include "call" and "uninstall," indicating potential application removal on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium151Free2022-01-28Windows: whoami.exe Executed by Privileged Accounts
Flags execution of whoami.exe from privileged-like accounts using Windows process creation events.
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh154Free2022-01-28Windows: Detect XORDump Utility Launch With LSASS Dump and Debug Module Switches
Alerts on xordump.exe spawning with LSASS-targeting and dump-module switches indicative of credential theft.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2022-01-28