Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Azure Kubernetes Service Service Account Modified or Deleted Activity Log Events
Alerts on Azure Activity Log events where a Kubernetes service account is written, deleted, or impersonated.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium122Free2021-08-07Azure Kubernetes Activity Logs: Write/Delete of ConfigMaps or Secrets
Alerts on Azure AKS activity log operations that write or delete Kubernetes ConfigMaps or Secrets.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium286Free2021-08-07Azure Kubernetes RBAC RoleBinding/ClusterRoleBinding Written or Deleted
Alerts on Azure Kubernetes RBAC RoleBinding/ClusterRoleBinding write or delete events that may indicate permission changes.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium356Free2021-08-07Azure Activity Logs: Kubernetes ClusterRole/Role Write, Delete, Bind, or Escalate Changes
Alerts on Azure Kubernetes RBAC Role/ClusterRole writes, deletions, bind, or escalation actions in activity logs.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium254Free2021-08-07Azure Activity Logs: Kubernetes Network Policy Write/Delete Changes
Alerts on Azure Activity Log events that modify or remove Kubernetes network policies for connected clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium92Free2021-08-07Azure Activity Logs: Azure Kubernetes Connected Cluster Created or Deleted
Alerts on Azure Activity Log operations that write or delete Kubernetes Connected Clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsLow153Free2021-08-07Azure Activity Logs: Container Registry Created or Deleted
Flags Azure Activity Log events where an Azure Container Registry is created (write) or deleted.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsLow352Free2021-08-07Detects ProxyShell-Style Exchange Probing via /autodiscover.json and PowerShell URIs (HTTP 401)
Flags Exchange web requests with ProxyShell-like /autodiscover.json query patterns and PowerShell/EWS-related parameters, often returning HTTP 401.
Florian Roth (Nextron Systems), Rich Warren, Huntrule Team—webserverHigh218Free2021-08-07Windows AnyDesk Silent Installation via Command-Line Flags
Identifies AnyDesk being silently installed on Windows using --install, --start-with-win, and --silent command-line flags.
Ján Trenčanský, Huntrule TeamWindowsprocess_creationHigh163Free2021-08-06Windows esentutl Usage with /p Flag for Credential Access
Flags Windows executions of esentutl when used with the /p parameter to access credentials-related files.
sam0x90, Huntrule TeamWindowsprocess_creationMedium92Free2021-08-06Windows Registry: Tamper Protection Disabled in Microsoft Defender Features
Flags registry changes that set Microsoft Defender Tamper Protection to disabled (DWORD 0x0), excluding expected MsMpEng update activity.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium3110Free2021-08-04Windows Registry: Disabling Windows Defender PUA Protection via PUAProtection DWORD
Flags registry changes that set Windows Defender PUAProtection DWORD to 0x00000000 to disable PUA protection.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setHigh186Free2021-08-04Windows Registry: Disable Windows Defender Exploit Guard Network Protection via Policy Override
Alerts on registry policy changes that override Exploit Guard Network Protection settings for Windows Defender.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium101Free2021-08-04Windows process access matching Cobalt Strike BOF injection call trace
Flags suspicious Windows process access consistent with CobaltStrike BOF injection using ntdll/KERNELBASE call traces and high GrantedAccess.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh133Free2021-08-04PowerShell timestomping via file timestamp property and setter usage (Windows)
Identifies PowerShell timestomping attempts by matching script text that sets file creation, access, and write timestamps.
frack113, Huntrule TeamWindowsps_scriptMedium182Free2021-08-03