Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
GitHub audit: New Actions secret created for org, environment, repo, or Codespaces
Triggers on GitHub audit events when an actor creates a new Actions secret for org, environment, Codespaces, or repo.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditLow229Free2023-01-20Windows DNS Client: DNS queries containing "ufile.io"
Alerts on Windows DNS Client queries where the queried name includes "ufile.io".
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientLow173Free2023-01-16Windows AppX Execution of Sysinternals Tools (procdump/psloglist/psexec/livekd/ADExplorer)
Flags execution of common Sysinternals binaries when launched through the Windows AppX runtime.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappmodel-runtimeLow316Free2023-01-16PowerShell script alias obfuscation via -Value (-join(...))
Flags PowerShell script blocks that set aliases using -Value with a (-join(...)) character-joining obfuscation pattern.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow417Free2023-01-09Juniper BGP Logs: Missing MD5 Digest in Route Authentication
Flags Juniper BGP log messages indicating a missing MD5 digest, highlighting potential exposure from unauthenticated routing sessions.
Tim Brown, Huntrule TeamJuniperbgpLow91Free2023-01-09Huawei BGP Authentication Failures Indicating Failed Session Attempts
Flags Huawei BGP authentication failure log events that may indicate credential attempts or routing manipulation.
Tim Brown, Huntrule TeamHuaweibgpLow246Free2023-01-09Cisco LDP MD5 Authentication Failure Events
Flags Cisco LDP TCP MD5 authentication failure events that may indicate brute-force attempts to affect MPLS label signaling.
Tim Brown, Huntrule TeamCiscoldpLow82Free2023-01-09Cisco BGP Authentication Failure Events Indicating Potential Credential Attacks
Flags Cisco BGP authentication failure events associated with TCP/179 traffic that may indicate credential abuse.
Tim Brown, Huntrule TeamCiscobgpLow268Free2023-01-09Windows PowerShell Script Block Alerts for Set-Alias and New-Alias Usage
Alerts on PowerShell scripts that create aliases via Set-Alias/New-Alias, a common obfuscation technique, using ScriptBlockText logging.
frack113, Huntrule TeamWindowsps_scriptLow485Free2023-01-08AWS CloudTrail: Potential S3 Bucket Enumeration via ListBuckets by Non-AssumedRole
Identifies S3 ListBuckets calls in CloudTrail that are not from assumed-role identities, which may indicate bucket discovery activity.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamAwscloudtrailLow142Free2023-01-06Linux auditd: Access to hidden files or hidden directories (/. paths)
Alerts when Linux auditd shows PATH values referencing hidden files or hidden directories (excluding common dev/cache paths).
David Burkett, @signalblur, Huntrule TeamLinuxauditdLow178Free2022-12-30Linux Privilege Capability Discovery via getcap
Flags Linux executions of /getcap with -r to recursively enumerate file capabilities during discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow162Free2022-12-28Windows ETW Logging Disabled via SCM Registry TracingDisabled Key
Detects SCM ETW logging being disabled by setting the TracingDisabled registry DWORD for services.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow152Free2022-12-09Windows Registry Change Disables ETW for rpcrt4.dll via ExtErrorInformation
Flags Windows registry updates that disable ETW logging for rpcrt4.dll through ExtErrorInformation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow325Free2022-12-09Windows Defender SubmitSamplesConsent Disabled (Real-Time Protection)
Flags Windows Defender configuration changes disabling automatic sample submission (SubmitSamplesConsent=0x0).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendLow349Free2022-12-06