Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Flags Windows Hybrid Connection Manager-related events mentioning sb:// and servicebus.windows.net.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsmicrosoft-servicebus-clientHigh82Free2021-04-12Windows Security Event 4697: HybridConnectionManager Service Installation
Alerts on HybridConnectionManager service installation on Windows via Security Event ID 4697.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh3310Free2021-04-12Windows Registry: Outlook Macro Security Level Set to Enable All Macros
Detects Outlook macro warning bypass by setting the Outlook security level registry value to enable all macros.
"@ScoubiMtl, Huntrule Team"Windowsregistry_setHigh101Free2021-04-05Windows Persistence: Outlook LoadMacroProviderOnBoot Registry Setting Modification
Alerts on enabling the Outlook LoadMacroProviderOnBoot registry setting, which can allow automatic VBA module loading at startup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh338Free2021-04-05Windows: New Outlook VBAProject OTM Macro File Created
Flags Windows file creation of Outlook VBAProject.OTM when initiated by outlook.exe.
"@ScoubiMtl, Huntrule Team"Windowsfile_eventMedium102Free2021-04-05Windows Exchange Management: Set-OabVirtualDirectory ExternalUrl to script content
Detects Exchange Management changes to OAB ExternalUrl containing script indicators and Page_Load.
Jose Rodriguez @Cyb3rPandaH, Huntrule TeamWindowsmsexchange-managementHigh296Free2021-03-15Windows schtasks.exe Creating One-Time Scheduled Tasks Using Temp Folder
Alerts on schtasks.exe commands that create one-time scheduled tasks referencing a Temp directory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh439Free2021-03-11Windows: Suspicious Service Binary Executed from Public/System Directories
Alerts on service-hosted processes executing from user/public or system-writable directories on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2021-03-09Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical172Free2021-03-09Windows Registry: VBScript/HTMLApplication Payload Stored Under Run Keys
Flags registry persistence where script payload indicators like vbscript: and RunHTMLApplication appear in set registry values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh235Free2021-03-05Windows Process Creation: rundll32.exe Command Line Invoking .sys Files
Flags Windows rundll32.exe executions whose command line references .sys file patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2021-03-05Windows rundll32 Executing Inline VBScript via RegRead
Detects rundll32.exe command lines containing inline VBScript execution with RegRead and window.close.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh388Free2021-03-05Windows Process Command Line: Suspicious Inline VBScript with UN2452-Like Keywords
Alerts on Windows command lines containing inline VBScript keywords and registry access indicators matching the UNC2452 UN2452 pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2021-03-05Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Flags PowerShell executions that Add-PSSnapin Exchange snap-ins, consistent with Exchange mailbox/config data collection.
FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh286Free2021-03-03Windows PowerShell TcpClient reverse-shell connection attempt via Net.Sockets
Alerts on PowerShell processes launching with .NET TcpClient stream/write patterns consistent with reverse TCP connectivity.
FPT.EagleEye, wagga, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2021-03-03