Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Google Workspace Admin: Application Removed from Domain
Flags Google Workspace domain events indicating an application was removed, including allowlist/whitelist removal.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium123Free2021-08-26Azure AD Hybrid Health AD FS Service Deletion via Azure Activity Logs
Flags Azure AD Hybrid Health AD FS service deletions from Azure Activity Logs under the Administrative category.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamAzureactivitylogsMedium151Free2021-08-26Azure Activity Logs: AD Hybrid Health AD FS server instance create/update
Alerts on Administrative Azure Activity Log events adding/updating AD Hybrid Health AD FS service member servers.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamAzureactivitylogsMedium1910Free2021-08-26MODX Manager Path Traversal Attempt via tvs.php class_key (CVE-2010-5278)
Alerts on HTTP requests to MODx tvs.php with traversal-based class_key payload indicative of LFI attempts.
Subhash Popuri (@pbssubhash), Huntrule Team—webserverCritical161Free2021-08-25Google Workspace Admin: Detect Role Privilege Deletion (REMOVE_PRIVILEGE)
Triggers on Google Workspace role privilege removal events (REMOVE_PRIVILEGE) in Admin audit logs.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium102Free2021-08-24Google Workspace Admin Role Modified or Deleted via admin.googleapis.com Audit Events
Identifies Google Workspace role updates, renames, or deletions from admin.googleapis.com audit events.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium279Free2021-08-24Web Exploitation of Arcadyan Router Path Traversal and Config Injection Attempts
Detects Arcadyan router exploit traffic by matching URL-encoded path traversal patterns in query strings linked to config injection.
Bhabesh Raj, Huntrule Team—webserverCritical389Free2021-08-24Windows Registry UAC Bypass Attempt via Windows Media Player osk.exe AppCompatFlags
Identifies registry AppCompatFlags entries for Windows Media Player osk.exe that may indicate a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2021-08-23Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-23Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.
Vadim Khrykov, Cyb3rEng, Huntrule TeamWindowsprocess_creationHigh162Free2021-08-23Windows UAC bypass using wsreset.exe with high/SYSTEM integrity
Alerts when wsreset.exe is executed with elevated integrity (High or SYSTEM), indicating a potential UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2021-08-23Windows Process UAC Bypass via Windows Media Player osksupport.dll (osk.exe → cmd.exe)
Alerts on osk.exe spawning cmd.exe under mmc event viewer with high/system integrity, consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2021-08-23Windows UAC Bypass via pkgmgr.exe Launching dism.exe (High/System Integrity)
Detects pkgmgr.exe spawning dism.exe with High/System integrity levels on Windows, a pattern used in UAC bypass attempts.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh418Free2021-08-23Windows UAC Bypass via consent.exe and werfault.exe with comctl32.dll-related behavior
Alerts on consent.exe parent launching werfault.exe with high/system integrity levels, consistent with potential UAC bypass attempts.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh295Free2021-08-23Windows UAC bypass via changepk.exe launched from slui.exe with elevated integrity
Flags changepk.exe execution from slui.exe with High/System integrity to identify potential UAC bypass behavior on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2021-08-23