Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,308 rules
Linux eBPF Backdoor File Persistence via cron.d and sudoers.d (ebpfbackdoor)
Detects Linux creation of "ebpfbackdoor" files in cron.d/sudoers.d, indicating likely persistence via an eBPF backdoor.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxfile_eventHigh103Free2022-07-05Linux eBPF Rootkit Activity: File Creation of /tmp/rootlog
Detects creation of /tmp/rootlog on Linux, a marker used by the TripleCross rootkit to track backdoor state.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxfile_eventHigh71Free2022-07-05Windows Registry Changes Disabling Windows Defender Event Log Channel
Detects registry changes that disable the Windows Defender Operational event log channel by setting its Enabled DWORD to 0.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh394Free2022-07-04Windows Registry Event Log Tampering by Disabling WINEVT Channel Enabled Key
Flags registry changes that set WINEVT channel Enabled to 0x00000000 to disable Windows event logging.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh223Free2022-07-04Windows UAC Bypass via IDiagnosticProfileUAC Triggered from DllHost.exe
Flags elevated process creation where DllHost.exe launches using the specific IDiagnosticProfileUAC /Processid value.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh257Free2022-07-03Windows: DllHost.exe creates a System32 DLL for UAC bypass via IDiagnosticProfileUAC
Alerts when dllhost.exe creates a System32 .dll consistent with IDiagnosticProfileUAC UAC bypass behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh343Free2022-07-03Windows: Suspicious LSASS handle access via svchost.exe call trace to seclogon.dll
Flags svchost.exe attempting LSASS access (granted access 0x14c0) with seclogon.dll in the call trace.
Samir Bousseaden (original elastic rule), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh294Free2022-06-29Windows: assoc.exe Changes File Extension Handler to exefile
Alerts on cmd.exe running assoc to set file extension handlers to exefile, indicating possible persistence via file associations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-06-28Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Flags bitsadmin.exe file downloads that target suspicious folders using /transfer, /create, and /addfile command-line parameters.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-06-28Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Flags bitsadmin.exe commands that transfer or add files with suspicious extensions based on process creation command-line content.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2022-06-28Windows BITSAdmin Downloads from File-Sharing Domains
Alerts on BITSAdmin downloads from popular file-sharing domains when transfer/create/addfile command-line flags are present.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-06-28Windows Process Creation: bitsadmin Download Using Direct IP URL
Alerts when bitsadmin.exe is used to download via a direct IP address in the command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-06-28Windows attrib.exe sets hidden system file attribute (+s) on suspicious paths and script/executable extensions
Flags attrib.exe usage with +s to mark .exe/.dll and script files in public/temp/user-writable locations as system files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-06-28PowerShell disables or removes ETW Trace via Set-EtwTraceProvider or Remove-EtwTraceProvider
Flags PowerShell commands that remove or disable ETW trace providers to impair Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-06-28Windows BITS Transfer Job Download to Suspicious File Paths
Flags new Windows BITS transfer jobs that save downloaded files into predefined suspicious paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientHigh2810Free2022-06-28