Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.
Bhabesh Raj, Huntrule TeamWindowssystemCritical3010Free2021-05-06Windows Driver File MoriyaStreamWatchmen.sys Created in System32\drivers
Alerts when the Windows system32 drivers directory receives the MoriyaStreamWatchmen.sys file.
Bhabesh Raj, Huntrule TeamWindowsfile_eventCritical141Free2021-05-06Windows whoami.exe Privilege Enumeration Using /priv Flag
Alerts on whoami.exe runs with /priv or -priv to enumerate current user privileges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2021-05-05Linux Code Injection via ld.so Preload File (/etc/ld.so.preload)
Alerts on references to /etc/ld.so.preload, indicating possible dynamic-library injection persistence on Linux.
Christian Burkard (Nextron Systems), Huntrule TeamLinux—High367Free2021-05-05Windows Pingback backdoor via ICMP C2 using updata.exe command-line parameters
Flags Windows process creation where updata.exe spawns msdtc config start auto commands consistent with Pingback backdoor.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh92Free2021-05-05Windows DLL Loading of C:\Windows\oci.dll by msdtc.exe
Flags msdtc.exe loading C:\Windows\oci.dll, consistent with Pingback backdoor DLL loading behavior.
Bhabesh Raj, Huntrule TeamWindowsimage_loadHigh468Free2021-05-05Windows File Indicator for Pingback Backdoor updata.exe Writing oci.dll
Alerts on updata.exe creating or modifying C:\Windows\oci.dll as a Pingback backdoor file indicator.
Bhabesh Raj, Huntrule TeamWindowsfile_eventHigh224Free2021-05-05Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh386Free2021-05-03Windows Security: Hidden Local User Account Creation (Event ID 4720)
Alerts on Windows 4720 local user creation for hidden accounts (username ending with '$'), excluding 'HomeGroupUser$'.
Christian Burkard (Nextron Systems), Huntrule TeamWindowssecurityHigh70Free2021-05-03Windows Process Access to svchost.exe with Credential Dumping Access Rights
Alerts on attempts to read svchost.exe memory consistent with credential dumping, excluding known benign callers.
Florent Labouyrie, Huntrule TeamWindowsprocess_accessHigh333Free2021-04-30PowerShell Defender Exclusion via Set/Add-MpPreference Command-Line Flags (Windows)
Detects PowerShell commands that add or set Microsoft Defender exclusions using Add/Set-MpPreference parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium316Free2021-04-29Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh112Free2021-04-23PowerShell ScriptBlock Certificate Export via Export-PfxCertificate or Export-Certificate
Detects PowerShell script blocks invoking certificate export cmdlets, which may be abused to steal sensitive certificate material.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptMedium81Free2021-04-23Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Flags HybridConnectionManager-initiated DNS queries to servicebus.windows.net on Windows.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsdns_queryHigh116Free2021-04-12