Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PortProxy Registry Key Modified for Port Forwarding
Alerts when PortProxy port-forwarding registry entries under the Windows TCP v4tov4 path are added or modified.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_eventMedium453Free2021-06-22Windows: Detect execution of renamed megasync.exe (original MegaSync) via process creation
Flags process launches where megasync.exe appears under a renamed or nonstandard execution context based on process creation fields.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh4610Free2021-06-22Windows LDAP Client Event ID 30 Active Directory enumeration via LDAP search filters
Flags LDAP search queries indicative of Active Directory reconnaissance/enumeration using Event ID 30 filter patterns.
Adeem Mawani, Huntrule TeamWindowsldapMedium429Free2021-06-22Windows: Suspicious Child Process Spawned by scrcons.exe (Script Event Consumer)
Alerts on rare child processes spawned by scrcons.exe, which may indicate abuse of Script Event Consumer for execution.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh393Free2021-06-21Windows Registry: New TaskCache entry created by unusual process image
Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.
Syed Hasan (@syedhasan009), Huntrule TeamWindowsregistry_setHigh212Free2021-06-18Windows Execution of PurpleSharp HackTool by Image Name or Executable Metadata
Alerts on process creation events consistent with running PurpleSharp.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical191Free2021-06-18Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.
MSTIC, FPT.EagleEye, Huntrule TeamWindowsprocess_creationHigh183Free2021-06-15Windows: Process writes registry to disable storage write-protection
Alerts on Windows process command lines that appear to disable storage write-protection via registry modification.
Sreeman, Huntrule TeamWindowsprocess_creationMedium181Free2021-06-11Windows Registry Set—Custom Outlook Today Page for Persistence
Flags registry writes that configure a custom Outlook Today URL using Outlook Today registry values.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh339Free2021-06-10Windows Persistence Attempt Using Outlook.exe to Create Outlook Forms Cache
Flags Outlook (outlook.exe) form file activity targeting local FORMS directories often used for persistence.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsfile_eventHigh201Free2021-06-10Windows Registry Changes for Outlook WebView Home Page URL Persistence
Alerts on Windows registry modifications affecting Outlook WebView home page URL settings.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh454Free2021-06-09BabyShark HackTool Proxy C2 URL Pattern via momyshark?key=
Alerts on proxy URIs containing the BabyShark agent default "momyshark?key=" query pattern.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical123Free2021-06-09Windows Registry: Microsoft Office Protected View Disabled via Security Policy Keys
Flags Windows registry updates that disable Microsoft Office Protected View for attachments, internet files, UNC paths, or unsafe locations.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh252Free2021-06-08Windows Process Creation: Exchange Transport Agent Installation via Install-TransportAgent
Flags Windows command-line executions containing Install-TransportAgent, indicating Exchange Transport Agent installation activity.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium241Free2021-06-08Windows MSExchange: Failed Transport Agent Installation (Install-TransportAgent)
Alerts on EventID 6 Exchange management events that include "Install-TransportAgent", indicating a failed Transport Agent installation attempt.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh4210Free2021-06-08