Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
RPC Firewall: Remote MS-EFSR encryption interface calls (EventID 3)
Alerts on RPC Firewall events targeting MS-EFSR interface UUIDs associated with remote encrypting file system abuse.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh151Free2022-01-01RPC Firewall Alerts for MS-DRSR DCSync Operations From Non-DC Hosts
Alerts on MS-DRSR RPC Firewall events where non-standard opcodes target the DRSR interface from non-DC hosts.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh288Free2022-01-01RPC Firewall AtScv Remote Schedule Task Information Recon
Identifies remote AtScv RPC calls that access scheduled task information via RPC Firewall telemetry.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh297Free2022-01-01Windows ATSvc Remote RPC Scheduled Task Creation or Execution (RPC Firewall)
Identifies remote ATSvc RPC calls for scheduled task creation/execution using RPC Firewall EventID 3 and OpNum 0/1.
Sagie Dulce, Dekel Paz, Huntrule TeamRpc_firewallapplicationHigh454Free2022-01-01Windows Winlogon Notify Registry Key DLL Persistence (logon)
Alerts on DLL-specified Winlogon Notify logon entries created via registry set events.
frack113, Huntrule TeamWindowsregistry_setHigh272Free2021-12-30Windows Registry Modification of Application Shim Database (InstalledSDB/Custom) for Persistence
Alerts on registry changes to Windows AppCompatFlags InstalledSDB/Custom that may enable shim-based persistence.
frack113, Huntrule TeamWindowsregistry_setMedium121Free2021-12-30Windows Registry: Add Print Port Monitor DLL Persistence
Flags registry updates to Print Port Monitors that reference .dll components for potential startup persistence on Windows.
frack113, Huntrule TeamWindowsregistry_setMedium442Free2021-12-30Windows Reg.exe Modifies Service ImagePath in HKLM\SYSTEM\CurrentControlSet\Services
Alerts on reg.exe commands that target HKLM\SYSTEM\CurrentControlSet\Services\ImagePath modifications.
frack113, Huntrule TeamWindowsprocess_creationMedium415Free2021-12-30Windows PowerShell ScriptBlock checks for service registry ACL inspection
Flags PowerShell scripts that use Get-ACL to inspect service Registry keys under HKLM\SYSTEM\CurrentControlSet\Services.
frack113, Huntrule TeamWindowsps_scriptMedium161Free2021-12-30Windows PowerShell script sets COR_PROFILER environment variables for .NET CLR profiling
Alerts on PowerShell script blocks that set CLR profiler environment variables (COR_ENABLE_PROFILING/COR_PROFILER/COR_PROFILER_PATH).
frack113, Huntrule TeamWindowsps_scriptMedium152Free2021-12-30Windows: File creation of C:\program.exe enabling unquoted service path execution
Flags creation of C:\program.exe that can be used to hijack unquoted Windows service binary paths.
frack113, Huntrule TeamWindowsfile_eventHigh388Free2021-12-30Windows: Suspicious .SCR Screensaver File Creation
Alerts on creation of new .scr screensaver binaries on Windows, excluding known benign paths and a specific TiWorker case.
frack113, Huntrule TeamWindowsfile_eventMedium82Free2021-12-29Windows File Creation: Custom Application Shim Database Files Created
Flags creation of custom Application Shim database files in AppPatch custom directories on Windows.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium453Free2021-12-29Windows Registry Changes to Outlook Security Settings
Alerts on registry updates to Outlook security configuration keys on Windows, excluding direct Outlook.exe changes.
frack113, Huntrule TeamWindowsregistry_setMedium122Free2021-12-28Windows Registry Startup: Chrome VPN Extensions Installed via Extension Registry Keys
Flags Windows Registry updates that register VPN/proxy Chrome extensions via the Chrome Extensions update_url key.
frack113, Huntrule TeamWindowsregistry_setHigh91Free2021-12-28