Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux doas.conf Creation via /etc/doas.conf File Events
Alerts when /etc/doas.conf is created on a Linux host.
Sittikorn S, Teoderick Contreras, Huntrule TeamLinuxfile_eventMedium133Free2022-01-20Windows PowerShell XML Document Load Used for Execution
Flags PowerShell script blocks that use XML document loading combined with expression/command execution keywords.
frack113, Huntrule TeamWindowsps_scriptMedium3810Free2022-01-19PowerShell MsXml2.XmlHttp COM Object Instantiation
Alerts on PowerShell creating an MsXml2.XmlHttp COM object through New-Object -ComObject.
frack113, MatilJ, Huntrule TeamWindowsps_scriptMedium142Free2022-01-19Windows Registry: Disable Administrative Share Creation via LanmanServer Parameters
Flags registry writes that disable Windows administrative share auto-creation under LanmanServer parameters.
frack113, Huntrule TeamWindowsregistry_setMedium151Free2022-01-16Windows msiexec.exe Quiet MSI Installation with Installer Arguments
Flags msiexec.exe launched with -q plus MSI installer switches, indicating quiet installation behavior in Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationMedium70Free2022-01-16Windows: Suspicious msiexec.exe Command-Line Writes Install Logs with /Y
Alerts on suspicious msiexec.exe executions using the /Y argument that are not consistent with common installer locations.
frack113, Huntrule TeamWindowsprocess_creationMedium437Free2022-01-16Windows DISM Online Disable-Feature via DismHost.exe or Dism.exe
Flags Windows DISM/DismHost executions using /Online and /Disable-Feature, a common defense-impairment technique.
frack113, Huntrule TeamWindowsprocess_creationMedium144Free2022-01-16PowerShell ScriptBlock Logging: Set-MpPreference disables Windows Defender scanning or allows threats
Alert on PowerShell Set-MpPreference usage that disables Defender scanning/monitoring or sets threat default actions to Allow.
frack113, elhoim, Tim Shelton (fps, alias support), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh342Free2022-01-16Windows: Deletion of TeamViewer log files
Alerts on deletion of TeamViewer *.log files on Windows, excluding deletions performed by svchost.exe.
frack113, Huntrule TeamWindowsfile_deleteLow161Free2022-01-16Windows msiexec.exe Initiates Outbound HTTP(S) Connection on Port 80/443
Alerts when msiexec.exe starts outbound connections to ports 80 or 443, indicating potential remote package retrieval.
frack113, Huntrule TeamWindowsnetwork_connectionLow90Free2022-01-16Windows rmdir Directory Removal via cmd.exe Execution
Monitors cmd.exe process creation where rmdir is used with /s and/or /q to delete directories and reduce forensic artifacts.
frack113, Huntrule TeamWindowsprocess_creationLow70Free2022-01-15Windows del/erase Command-Line File Deletion via cmd.exe
Flags cmd.exe executions running del/erase for file removal, including common flags like /f, /s, and /q.
frack113, Huntrule TeamWindowsprocess_creationLow229Free2022-01-15Windows PowerShell: Start-Process with -PassThru and -FilePath
Alerts on PowerShell Start-Process calls that include -PassThru and -FilePath, based on ScriptBlockText matches.
frack113, Huntrule TeamWindowsps_scriptMedium131Free2022-01-15Windows PowerShell ScriptBlock Use of Remove-Item to Delete Files or Folders
Alerts on PowerShell ScriptBlockText containing Remove-Item/del/rm/rd-style -Path deletion commands.
frack113, Huntrule TeamWindowsps_scriptLow60Free2022-01-15Windows Process Creation: VMware Horizon Log4j RCE Attempt via ws_TomcatService to cmd/powershell
Alert on ws_TomcatService.exe spawning cmd.exe or PowerShell on Windows as suspicious exploitation activity.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh142Free2022-01-14