Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Office Macro File Creation from Browser or Email Client
Flags Windows creation of macro-enabled Office files (.docm/.xlsm/.pptm) initiated by common browsers or email clients.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow187Free2022-01-23Windows Office Macro File Creation via Office Applications
Alerts on creation of macro-enabled Office documents/templates by Office apps on Windows, excluding Office temporary files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow161Free2022-01-23Windows curl.exe Execution Using Custom User-Agent Flags
Flags Windows process launches of curl.exe with -A/--user-agent parameters to set a custom user agent.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2022-01-23Windows Registry: Internet Settings Zone and Cache-related Key Modifications
Flags registry writes to Windows Internet Settings-related keys that can be abused to alter zone trust or store persistence data.
frack113, Huntrule TeamWindowsregistry_setLow133Free2022-01-22Windows Registry Set to Hide File Extensions via Explorer Advanced Keys
Flags registry changes under Explorer Advanced that hide file extensions by setting specific DWORD values.
frack113, Huntrule TeamWindowsregistry_setMedium168Free2022-01-22Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Flags Windows registry changes to IE ZoneMap domain entries that alter security zone assignments for targeted domains.
frack113, Huntrule TeamWindowsregistry_setMedium2910Free2022-01-22Radmin Viewer Utility Execution on Windows (Process Creation)
Alerts when Radmin Viewer (Radmin.exe) is launched, based on process metadata in Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationMedium195Free2022-01-22Windows Network Connection Initiated by IMEWDBLD.EXE
Alerts when IMEWDBLD.EXE initiates a network connection on Windows.
frack113, Huntrule TeamWindowsnetwork_connectionHigh151Free2022-01-22Linux Auditd: Stop Firewalld, iptables, or UFW Services
Detects stopping firewall services (firewalld/iptables/ufw) on Linux via auditd service-stop events.
Pawel Mazur, Huntrule TeamLinuxauditdHigh163Free2022-01-22Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color
Alerts on colorcpl.exe creating files in C:\Windows\System32\spool\drivers\color\ with suspicious target filenames.
frack113, Huntrule TeamWindowsfile_eventHigh166Free2022-01-21Windows Kerberoasting Initial Query: Successful 4769 RC4 Service Requests with Filters
Collects successful Windows 4769 RC4 service-ticket requests while excluding krbtgt and computer/service account patterns for kerberoasting triage.
"@kostastsale, Huntrule Team"WindowssecurityMedium343Free2022-01-21Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Detects AdvancedRun execution where /RunAs is set to specific high-privilege IDs in the process command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-01-20Windows PUA AdvancedRun.exe Execution
Detects AdvancedRun.exe executions on Windows with /Run and /RunAs style command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-01-20Windows Code Integrity: Unmet Signing Level Requirements When Loading a File (Event ID 3033/3034)
Alerts on Code Integrity file-load attempts failing signing level requirements, based on Event ID 3033/3034 in Windows Code Integrity logs.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalLow152Free2022-01-20Linux doas Command Execution Identified
Flags Linux executions of the doas utility based on process image path ending with /doas.
Sittikorn S, Teoderick Contreras, Huntrule TeamLinuxprocess_creationLow71Free2022-01-20