Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Azure Audit Logs: Application Deletion (Delete/Hard Delete) Detected
Flags Azure audit events where an application (or administrative unit) is deleted, including hard deletes.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium102Free2021-09-03Azure Activity Logs: Device or Device Configuration Modified or Deleted
Flags Azure audit events indicating device or device configuration updates or deletions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium81Free2021-09-03PowerShell ScriptBlock launching redirected comspec to Alternate Data Stream via '>'
Flags PowerShell script blocks using Start-Process with comspec and " > " redirection consistent with ADS-style file hiding.
frack113, Huntrule TeamWindowsps_scriptMedium93Free2021-09-02Windows Kerberos TGT Request with AD CS Certificate Thumbprint Anomalies (EventID 4768)
Identifies unusual certificate-associated Kerberos TGT (4768) requests targeting computer accounts on Windows.
Mauricio Velazco, Michael Haag, Huntrule TeamWindowssecurityHigh82Free2021-09-02Azure Audit Logs: Service Principal Created via Add service principal
Alerts on Azure audit log events that add a new service principal.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium121Free2021-09-02Azure Network Firewall Policy Modified or Deleted via Activity Logs
Alerts on Azure Activity Log operations that modify or delete Network Firewall Policies.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium279Free2021-09-02Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowswmi_eventHigh364Free2021-09-01Windows Process Creation: Execution CommandLines Involving NTFS Alternate Data Streams
Alerts on Windows executions whose command lines reference NTFS Alternate Data Streams combined with specific file-data tools.
frack113, Huntrule TeamWindowsprocess_creationMedium2310Free2021-09-01Windows WMI Event Consumer (scrcons.exe) Creates Named Pipe
Flags scrcons.exe creating a Windows named pipe, using named pipe creation event telemetry.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdMedium187Free2021-09-01Windows Atera RMM Agent Installation via MsiInstaller Event ID 1033
Flags Windows MSI installs where installer logs indicate an AteraAgent installation (EventID 1033, MsiInstaller).
Bhabesh Raj, Huntrule TeamWindowsapplicationHigh112Free2021-09-01Windows UAC Bypass via ComputerDefaults.exe with Elevated Integrity Parent Process
Flags ComputerDefaults.exe runs at high/system integrity when the parent isn’t from typical system or Program Files paths.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2021-08-31Windows Registry UAC Bypass via winsat.exe LowerCaseLongPath and UACMe Path Parsing
Matches registry writes that reference winsat.exe using a LowerCaseLongPath construction consistent with UAC bypass path parsing.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh169Free2021-08-30Windows Process Creation: UAC Bypass via winsat.exe Path Parsing
Alerts on elevated processes spawned by Temp-path winsat.exe with system32 winsat command-line content.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh434Free2021-08-30Windows UAC Bypass via NTFS Reparse Point: wusa.exe DLL Hijacking Process Behavior
Alerts on high-integrity wusa.exe launched from Temp update.msu with a dism.exe parent showing DismHost activity.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2021-08-30Windows UAC Bypass via msconfig Token Modification (msconfig.exe -5) Process Creation
Flags msconfig.exe invoked with -5 from a Temp pkgmgr.exe parent under elevated integrity levels, indicating a possible UAC bypass.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-08-30