Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,308 rules
Windows BITS Client Downloads From File-Sharing Domains
Alerts on Windows BITS transfers (EventID 16403) that download from known file-sharing/content hosting domains.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientHigh122Free2022-06-28Azure AD Sign-ins from Non-Compliant Devices
Alert on Entra ID sign-ins originating from devices flagged as non-compliant.
Michael Epping, '@mepples21', Huntrule TeamAzuresigninlogsHigh211Free2022-06-28Azure Audit Logs: User Added to Global or Device Administrator Roles
Alerts when Azure AD role-management events add users to Global or Device Administrator roles.
Michael Epping, '@mepples21', Huntrule TeamAzureauditlogsHigh315Free2022-06-28Azure AD/Entra Audit Logs: Device Registration Policy Changes
Alerts on Azure audit log events that set or modify the device registration policy.
Michael Epping, '@mepples21', Huntrule TeamAzureauditlogsHigh459Free2022-06-28Windows dllhost.exe Launched With No Command-Line Arguments
Alerts on dllhost.exe being executed with no command-line arguments, a rare pattern that may indicate stealthy or injected activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-06-27Windows HandleKatz: Duplicate LSASS Handle via Process Access with Handle Duplication Rights
Flags HandleKatz-style behavior duplicating an existing LSASS handle using PROCESS_DUP_HANDLE and ntdll.dll call trace.
Bhabesh Raj (rule), @thefLinkk, Huntrule TeamWindowsprocess_accessHigh255Free2022-06-27Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-06-27Windows: Potential Process Injection via Msra.exe Spawning Suspicious Child Processes
Flags Msra.exe spawning suspicious tools that may indicate process injection or post-exploitation activity on Windows.
Alexander McDonald, Huntrule TeamWindowsprocess_creationHigh162Free2022-06-24Linux Process Recon: Find SUID/htpasswd Files via Command-Line Patterns
Flags Linux command-line reconnaissance patterns for .htpasswd discovery and setuid (-perm -4000) file enumeration.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh348Free2022-06-20Linux Shell History File Deletion via rm/unlink/shred
Alert on Linux command-line history file deletions using rm/unlink/shred targeting bash/zsh history files.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh161Free2022-06-20Windows Registry: New W32Time TimeProvider DllName Values Set Under Services\W32Time\TimeProvider
Alerts on new or changed W32Time TimeProvider DllName registry values under Services\W32Time\TimeProvider.
frack113, Huntrule TeamWindowsregistry_setHigh132Free2022-06-19Windows: Chromium-Based Browser Launched via Script Host with --load-extension
Flags Windows process creation where Chromium browsers are spawned with --load-extension= from common script/LOLBins parents.
Aedan Russell, frack113, X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh100Free2022-06-19Windows File Events: Flag Files With Double Extensions (e.g., .docx.exe)
Alerts on Windows filenames that look like double extensions, including .rar.exe/.zip.exe masquerading patterns.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsfile_eventHigh193Free2022-06-19Windows: msdt.exe Loads sdiageng.dll via Image Load Events
Flags msdt.exe image-load events that load sdiageng.dll, a behavior commonly associated with DLL side-loading abuse.
Greg (rule), Huntrule TeamWindowsimage_loadHigh169Free2022-06-17Azure AD Sign-ins Using Legacy Authentication Client Applications
Alerts on Azure sign-ins using legacy protocol client apps (IMAP/POP3/SMTP/EWS/ActiveSync), which may indicate risky authentication usage.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsHigh152Free2022-06-17