Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,306 rules
Python Process Spawning a Pretty TTY via pty.spawn on Windows
Flags Windows python executions whose command line imports pty and calls pty.spawn to create a pseudo-terminal.
Nextron Systems, Huntrule TeamWindowsprocess_creationHigh4010Free2022-06-03Linux Java Process Launching Suspicious Shell and Scripting Children
Alerts when a Java parent process launches shell or downloader/scripting tools on Linux.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh90Free2022-06-03Linux process creation: Confluence Java spawning script or download utilities
Alerts when Confluence’s Java process on Linux spawns shell or scripting/utilities, consistent with potential CVE-driven command execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh81Free2022-06-03Windows Process Creation: BrowserCore.exe Renamed Execution for Azure Token Theft
Flags renamed BrowserCore.exe executions by matching OriginalFileName while the process image ends with BrowserCore.exe.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-06-02Windows Office Startup Folder File Drop for Persistence via Office Documents
Alerts when Office documents/templates are created in Word/Excel startup folders on Windows, suggesting persistence attempts.
Max Altgelt (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2022-06-02Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Alerts on Azure audit log events indicating an application URI (AppAddress) was modified.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh151Free2022-06-02Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes
Alerts on Azure audit log entries indicating updates to an application or service principal AppID URI configuration.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh101Free2022-06-02Windows Office Child Process with Directory Traversal Patterns
Alerts on Office parent processes launching child commands containing directory traversal patterns.
Christian Burkard (Nextron Systems), @SBousseaden (idea), Huntrule TeamWindowsprocess_creationHigh122Free2022-06-02Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Alert when sdiagnhost.exe launches high-risk child processes like PowerShell or CMD, excluding selected benign-like command patterns.
Nextron Systems, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh122Free2022-06-01Windows msdt.exe Execution with Suspicious Parent Process
Alerts when msdt.exe runs under common command-and-script or utility parent processes on Windows.
Nextron Systems, Huntrule TeamWindowsprocess_creationHigh254Free2022-06-01Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Alerts on Azure sign-ins blocked by Conditional Access when requirements are not met.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsHigh100Free2022-06-01Windows msdt.exe / ms-msdt Handler Arbitrary Command Execution Attempts
Alerts on Windows executions of msdt.exe with command-line indicators suggesting arbitrary command execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-05-29Windows Registry: OneDriveStandaloneUpdater.exe URL From UpdateOfficeConfig for Proxy Download
Alerts on registry settings that redirect OneDrive update URL retrieval from UpdateOfficeConfig for internet downloads.
frack113, Huntrule TeamWindowsregistry_setHigh188Free2022-05-28Windows PowerShell detects obfuscated Net.Webclient casing anomalies in command line
Alerts when PowerShell command lines contain encoded obfuscation patterns referencing Net.Webclient with anomalous casing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh229Free2022-05-24Windows PowerShell Process Command Lines With Encoded Command Flags
Alerts on PowerShell (pwsh) command lines using encoded command flags and encoded-looking substrings, excluding gc_worker.exe-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-05-24