Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,320 rules
Windows PowerShell Set-Service SDDL Usage to Hide Services
Flags pwsh Set-Service commands that set a SecurityDescriptorSddl to hide a Windows service from other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-10-17PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Flags PowerShell Set-Service calls that set a SecurityDescriptor SDDL (DCLCWPDTSD) to hide services from other utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh132Free2022-10-17Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Alerts on AD attribute changes adding to msDS-KeyCredentialLink via Windows Security EventID 5136, consistent with shadow credential additions.
Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowssecurityHigh246Free2022-10-17macOS Process Execution Traces Indicating WizardUpdate Downloader/C2 Staging
Flags macOS process creations showing curl+eval execution and intermediate agent indicators associated with WizardUpdate activity.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationHigh223Free2022-10-17Windows process execution: wermgr.exe running outside standard system directories
Alerts when wermgr.exe is launched from a non-standard directory on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh424Free2022-10-14Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2022-10-14Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)
Alerts on Windows Security Event 4649 indicating a Kerberos replay error (KRB_AP_ERR_REPEAT).
frack113, Huntrule TeamWindowssecurityHigh429Free2022-10-14Windows: ssh.exe RDP tunneling to :3389 via SSH
Alerts on Windows process executions of ssh.exe that reference RDP port :3389 for SSH tunneling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-10-12Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh113Free2022-10-10Windows MSSQL: Extended Stored Procedure execution with provider name MSSQLSERVER and message containing 'maggie'
Flags MSSQLSERVER extended stored procedure events where the message contains 'maggie', indicating potential backdoor usage.
Denis Szadkowski, DIRT / DCSO CyTec, Huntrule TeamWindowsapplicationHigh238Free2022-10-09Windows: NPS (npc.exe) Port Forwarding Proxy Execution via Command-Line Parameters
Flags Windows executions of npc.exe with NPS server, vkey/password, or config=npc command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh455Free2022-10-08Windows Execution of IOX (iex/port forwarding) Tunnel/Proxy Tool via Process Creation
Alerts on Windows process creation for iox.exe with tunneling/proxy forwarding command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2022-10-08Windows Process Creation: SharpWSUS or WSUSpendu Execution via PowerShell Parameters
Detects command-line execution patterns for SharpWSUS or WSUSpendu on Windows.
"@Kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh246Free2022-10-07Windows LPE Attempt via TabTip CLSID Using Microsoft-Windows-DistributedCOM (Event ID 10001)
Alerts when TabTip.exe is started via CLSID/DCOM activation in Windows DistributedCOM EventID 10001.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh61Free2022-10-07Windows Process Creation: GMER Rootkit Tool Execution (gmer.exe)
Flags execution of gmer.exe on Windows when matched by known process hashes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-10-05