Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Zeek DNS: Detect NKN Seed Domain Queries
Alerts on Zeek DNS queries containing "seed" and ending with .nkn.org, a pattern consistent with NKN network activity.
Michael Portera (@mportatoes), Huntrule TeamZeekdnsLow132Free2022-04-21Windows File Access to Browser Credential Stores by Uncommon Processes
Detects suspicious process access to Firefox/Chromium credential store files on Windows, excluding common system and known benign paths.
frack113, X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessLow60Free2022-04-09Windows Security: Outgoing Logon (LogonType 9) Using New Credentials (4624)
Flags Windows 4624 LogonType 9 events where new credentials are used for authentication.
Max Altgelt (Nextron Systems), Huntrule TeamWindowssecurityLow121Free2022-04-06Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
frack113, Huntrule TeamWindowsps_scriptLow153Free2022-04-04Windows fsutil.exe Drive Enumeration via Process Execution
Flags fsutil.exe process launches with command lines referencing connected drive enumeration.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow102Free2022-03-29Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
frack113, Huntrule TeamWindowsps_scriptLow133Free2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
frack113, Huntrule TeamWindowsps_scriptLow404Free2022-03-17Windows PowerShell Active Directory Group Enumeration via Get-AdGroup Cmdlet
Flags PowerShell script blocks that call Get-ADGroup with -Filter to enumerate Active Directory groups.
frack113, Huntrule TeamWindowsps_scriptLow163Free2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
frack113, Huntrule TeamWindowsps_scriptLow357Free2022-03-17Windows: Executable Creates Executable via File Creation Events
Flags .exe-to-.exe executable drops on Windows when a running executable creates another .exe, with exclusions for common system/update paths.
frack113, Huntrule TeamWindowsfile_eventLow70Free2022-03-09Windows BITS Job Creation Triggered by PowerShell
Flags new BITS job creation on Windows when initiated by PowerShell (Event ID 3).
frack113, Huntrule TeamWindowsbits-clientLow111Free2022-03-01Windows BITS job created by bitsadmin.exe (BITS Client EventID 3)
Alerts on new BITS job creation when bitsadmin.exe triggers it (BITS-Client EventID 3).
frack113, Huntrule TeamWindowsbits-clientLow133Free2022-03-01Windows Firewall Settings Change Events (Windows Firewall/Defender Firewall-AS)
Alert on Windows Firewall/Defender firewall setting changes using Events 2002, 2003, 2008, 2082, and 2083.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asLow142Free2022-02-19Windows Defender Firewall Reset to Default Configuration (Firewall-as Service)
Flags Windows where Windows Defender Firewall is reset to default settings via firewall-as events.
frack113, Huntrule TeamWindowsfirewall-asLow71Free2022-02-19Windows Defender Firewall Service Failed to Load Group Policy (Event ID 2009)
Alert on Event ID 2009 when the Windows Defender Firewall service cannot load Group Policy.
frack113, Huntrule TeamWindowsfirewall-asLow4210Free2022-02-19