Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows Firewall Exception List Rule Modified (Firewall-as Events 2005/2073)
Flags Windows Defender Firewall exception list changes (Event IDs 2005/2073), indicating potential attacker-driven network access changes.
frack113, Huntrule TeamWindowsfirewall-asLow80Free2022-02-19Windows: attrib.exe Executed with +s to Mark Files as System Files
Flags attrib.exe executions that include the +s switch to mark target files as system files.
frack113, Huntrule TeamWindowsprocess_creationLow60Free2022-02-04PowerShell Mount-DiskImage with -ImagePath to Access Disk Images
Alerts on PowerShell script blocks calling Mount-DiskImage with -ImagePath, indicative of disk-image-based payload staging.
frack113, Huntrule TeamWindowsps_scriptLow342Free2022-02-01Windows Installer Application Removed via MsiInstaller Events
Alerts on Windows Installer events indicating an application was removed via MsiInstaller.
frack113, Huntrule TeamWindowsapplicationLow131Free2022-01-28Windows PowerShell: Suspicious SslStream Client Certificate Validation in Script Block
Flags PowerShell scripts referencing SslStream and client-side certificate validation during SSL client authentication.
frack113, Huntrule TeamWindowsps_scriptLow143Free2022-01-23Windows Office Macro File Creation from Browser or Email Client
Flags Windows creation of macro-enabled Office files (.docm/.xlsm/.pptm) initiated by common browsers or email clients.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow187Free2022-01-23Windows Office Macro File Creation via Office Applications
Alerts on creation of macro-enabled Office documents/templates by Office apps on Windows, excluding Office temporary files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow161Free2022-01-23Windows Registry: Internet Settings Zone and Cache-related Key Modifications
Flags registry writes to Windows Internet Settings-related keys that can be abused to alter zone trust or store persistence data.
frack113, Huntrule TeamWindowsregistry_setLow133Free2022-01-22Windows Code Integrity: Unmet Signing Level Requirements When Loading a File (Event ID 3033/3034)
Alerts on Code Integrity file-load attempts failing signing level requirements, based on Event ID 3033/3034 in Windows Code Integrity logs.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalLow162Free2022-01-20Linux doas Command Execution Identified
Flags Linux executions of the doas utility based on process image path ending with /doas.
Sittikorn S, Teoderick Contreras, Huntrule TeamLinuxprocess_creationLow71Free2022-01-20Windows: Deletion of TeamViewer log files
Alerts on deletion of TeamViewer *.log files on Windows, excluding deletions performed by svchost.exe.
frack113, Huntrule TeamWindowsfile_deleteLow161Free2022-01-16Windows msiexec.exe Initiates Outbound HTTP(S) Connection on Port 80/443
Alerts when msiexec.exe starts outbound connections to ports 80 or 443, indicating potential remote package retrieval.
frack113, Huntrule TeamWindowsnetwork_connectionLow90Free2022-01-16Windows rmdir Directory Removal via cmd.exe Execution
Monitors cmd.exe process creation where rmdir is used with /s and/or /q to delete directories and reduce forensic artifacts.
frack113, Huntrule TeamWindowsprocess_creationLow70Free2022-01-15Windows del/erase Command-Line File Deletion via cmd.exe
Flags cmd.exe executions running del/erase for file removal, including common flags like /f, /s, and /q.
frack113, Huntrule TeamWindowsprocess_creationLow229Free2022-01-15Windows PowerShell ScriptBlock Use of Remove-Item to Delete Files or Folders
Alerts on PowerShell ScriptBlockText containing Remove-Item/del/rm/rd-style -Path deletion commands.
frack113, Huntrule TeamWindowsps_scriptLow60Free2022-01-15