Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,301 rules
Windows Process Execution: NSudo (NSudo.exe/NSudoLC/NSudoLG)
Alerts on NSudo execution on Windows with privilege and integrity/elevation command-line parameters.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh337Free2022-01-24Windows Process Creation: NirCmd runasSystem CommandLine Usage
Alerts on NirCmd being used to run commands as LocalSystem based on the process command line.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh252Free2022-01-24BlackByte ransomware Registry Set Persistence and Privilege Changes (Windows)
Alerts on BlackByte-specific Windows registry value changes to DWORD 1 across three predefined keys.
frack113, Huntrule TeamWindowsregistry_setHigh131Free2022-01-24Windows Office Macro File Creation Triggered by Script/LOLBin Parent Process
Alerts when macro-enabled Office files are created by common Windows script execution processes.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh153Free2022-01-23Windows Network Connection Initiated by IMEWDBLD.EXE
Alerts when IMEWDBLD.EXE initiates a network connection on Windows.
frack113, Huntrule TeamWindowsnetwork_connectionHigh151Free2022-01-22Linux Auditd: Stop Firewalld, iptables, or UFW Services
Detects stopping firewall services (firewalld/iptables/ufw) on Linux via auditd service-stop events.
Pawel Mazur, Huntrule TeamLinuxauditdHigh163Free2022-01-22Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color
Alerts on colorcpl.exe creating files in C:\Windows\System32\spool\drivers\color\ with suspicious target filenames.
frack113, Huntrule TeamWindowsfile_eventHigh166Free2022-01-21Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Detects AdvancedRun execution where /RunAs is set to specific high-privilege IDs in the process command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-01-20PowerShell ScriptBlock Logging: Set-MpPreference disables Windows Defender scanning or allows threats
Alert on PowerShell Set-MpPreference usage that disables Defender scanning/monitoring or sets threat default actions to Allow.
frack113, elhoim, Tim Shelton (fps, alias support), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh342Free2022-01-16Windows Process Creation: VMware Horizon Log4j RCE Attempt via ws_TomcatService to cmd/powershell
Alert on ws_TomcatService.exe spawning cmd.exe or PowerShell on Windows as suspicious exploitation activity.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh142Free2022-01-14Windows: Process creation event for Sysmon uninstall using Sysmon -u
Flags attempts to uninstall Sysmon on Windows by running Sysmon with the -u flag.
frack113, Huntrule TeamWindowsprocess_creationHigh439Free2022-01-12PowerShell Script Creates Volume Shadow Copy via Win32_ShadowCopy
Alerts when PowerShell script blocks invoke Win32_ShadowCopy.Create to create a ClientAccessible shadow copy.
frack113, Huntrule TeamWindowsps_scriptHigh171Free2022-01-12Windows ProcDump renamed, copied or moved for stealth evasion
Alerts on ProcDump commands that copy/move or rename dump outputs, including LSASS dump filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-01-11Windows regsvr32 Downloads Remote DLLs via HTTP/HTTPS IP in /i Parameter
Alerts when regsvr32 is invoked with an /i: HTTP/HTTPS IP pattern to fetch remote DLLs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2022-01-11Windows mpiexec.exe LOLBin: Flag combination with -n/n 1 for potential arbitrary execution
Alerts on Windows executions of mpiexec.exe with /n 1 or -n 1, correlated to a specific imphash, indicating LOLBin-style behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2022-01-11