Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows Security Event Add/Remove Computer Account (4741/4743)
Alerts on Windows domain computer account create/delete activity via Security event 4741 and 4743.
frack113, Huntrule TeamWindowssecurityLow80Free2022-10-14Windows Driver Load of Known Vulnerable Drivers by File Name
Alerts when Windows loads a driver whose filename matches a list of known vulnerable drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadLow133Free2022-10-03Process Creation: curl on Linux
Flags Linux process starts for the curl binary, indicating potential remote file download or web requests.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow90Free2022-09-15Windows Suspicious Process Execution Using GUID-Like Folder Names in %TEMP% or AppData
Hunts Windows processes whose command lines reference GUID-named folders in user AppData/Temp locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow100Free2022-09-01Windows: DirLister.exe Execution for Directory Listing Discovery
Alerts on execution of DirLister.exe on Windows, indicating potential directory/file discovery activity.
frack113, Huntrule TeamWindowsprocess_creationLow155Free2022-08-20Windows DNS Query for _ldap.* Using LDAP-Related Discovery
Alerts on _ldap.* DNS queries from uncommon Windows processes, indicating potential LDAP/DNS service discovery.
frack113, Huntrule TeamWindowsdns_queryLow141Free2022-08-20Windows: User Profiles Service EventID 1511 indicating potential CVE-2022-21919 or CVE-2021-34484 LPE
Alerts on User Profiles Service Event ID 1511, a possible signal of LPE exploitation attempts associated with CVE-2022-21919 or CVE-2021-34484.
Cybex, Huntrule TeamWindowsapplicationLow336Free2022-08-16Windows File Creation Time Altered to a Previous Year
Alerts on Windows events where a file’s creation time is altered to a different year, excluding common benign system/update tooling.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_changeLow90Free2022-08-12Azure Audit Logs: End User Consent for Application (Non-Admin Consent)
Identifies end-user consent grants to applications in Azure AD audit logs.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsLow135Free2022-07-28Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Alerts on successful Azure AD sign-ins where MFA was not required and only single-factor authentication was used.
MikeDuddington, '@dudders1', Huntrule TeamAzuresigninlogsLow90Free2022-07-27Windows curl.exe Process Creation
Alerts on execution of curl.exe on Windows, which may indicate remote downloads or web requests.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow90Free2022-07-05Azure AD Sign-ins from Unknown Devices with Single-Factor Authentication
Alerts on successful Azure sign-ins using single-factor authentication with unknown or missing device identifiers from non-trusted contexts.
Michael Epping, '@mepples21', Huntrule TeamAzuresigninlogsLow334Free2022-06-28Windows DNS Queries Containing ufile.io Domain
Alerts on Windows DNS lookups where the queried name contains ufile.io, indicating potential exfiltration-related activity.
yatinwad, TheDFIRReport, Huntrule TeamWindowsdns_queryLow90Free2022-06-23Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
frack113, Huntrule TeamWindowsps_scriptLow111Free2022-06-04Windows JScript Compiler (jsc.exe) Process Execution
Identifies execution of jsc.exe (JScript Compiler) from Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationLow185Free2022-05-02