Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
GCP Kubernetes audit events: Admission webhook configuration creates/updates
Flags GCP Kubernetes audit events indicating mutating/validating admission webhook configuration create/patch/replace activity.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium131Free2021-11-25Azure Activity Logs: Kubernetes AdmissionRegistration webhook configuration writes
Flags Azure activity log events writing Kubernetes admission webhook configurations (mutating or validating), indicating potential cluster request interception.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium152Free2021-11-25Windows: Rundll32 Loading shell32.dll via Control_RunDLL from User/Temp Paths
Alerts on rundll32.exe loading shell32.dll with Control_RunDLL from AppData/Temp/user paths.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2021-11-24Windows CertReq -Post Download Attempt via HTTP
Flags certreq.exe executions using -Post -config and HTTP content retrieval indicators.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh349Free2021-11-24Windows bash.exe Launched with -c for Indirect Inline Command Execution
Alerts on Windows processes starting bash.exe with -c, indicating inline command execution.
frack113, Huntrule TeamWindowsprocess_creationMedium421Free2021-11-24Windows: aspnet_compiler.exe Execution Detection
Detects execution of aspnet_compiler.exe from Windows .NET Framework directories, which can be abused to compile and run C#.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2021-11-24Windows DNS Queries Triggered by DesktopAppInstaller AppInstaller.EXE
Identifies DNS lookups performed by Windows AppInstaller.EXE when initiating ms-appinstaller package installation from a URL.
frack113, Huntrule TeamWindowsdns_queryMedium335Free2021-11-24Windows PsExec/PAExec Command-Line Flags Escalating to LOCAL SYSTEM
Flags in PsExec/PAExec command lines requesting LOCAL SYSTEM execution are matched via process creation command-line telemetry.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2021-11-23Windows process access to LSASS.exe with suspicious GrantedAccess flags
Alerts on process access attempts to lsass.exe with GrantedAccess rights commonly linked to credential theft behavior.
Florian Roth, Roberto Rodriguez, Dimitrios Slamaris, Mark Russinovich, Thomas Patzke, Teymur Kheirkhabarov, Sherif Eldeeb, James Dickenson, Aleksey Potapov, oscd.community, Huntrule TeamWindowsprocess_accessMedium402Free2021-11-22GCP Kubernetes CronJob or Job Creation via gcp.audit
Flags GCP audit events where Kubernetes batch Job/CronJob API methods indicate CronJob or Job execution setup.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium181Free2021-11-22Azure Activity Logs: Kubernetes CronJob or Job Write Operations
Detects Azure Activity Log write operations for Kubernetes CronJobs and Jobs that can schedule container workloads.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium162Free2021-11-22Windows MSIInstaller EventID 1033 PoC File Takeover String Match (InstallerFileTakeOver/CVE-2021-41379)
Alert on Windows MSI installer EventID 1033 with event data containing 'test pkg', consistent with PoC activity for CVE-2021-41379.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh197Free2021-11-22Windows Process Creation: cmd.exe Spawned from Edge Elevation Service (CVE-2021-41379)
Alerts when cmd.exe or PowerShell spawns under Edge elevation service with SYSTEM integrity, consistent with CVE-2021-41379 exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical183Free2021-11-22Windows MSI Exec Creates elevation_service.exe Under Edge Path (CVE-2021-41379)
Flags msiexec creating elevation_service.exe within the Microsoft Edge application directory, indicating potential LPE exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical82Free2021-11-22Windows Shell/Scripting Tool File Write to Suspicious Directories
Alert on file writes by common Windows shells/scripting tools to C:\PerfLogs, C:\Users\Public, or C:\Windows\Temp.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh143Free2021-11-20