Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,298 rules
Azure AuditLogs: Privileged role assignment to user access admin
Flags Azure AuditLogs events where a user is assigned to User Access Administrator, enabling full subscription management.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsHigh163Free2021-11-26Azure Activity Logs: Authorization ElevateAccess Grants Subscription-Level Management
Alerts on Azure Activity Log authorization elevation actions that can grant access to manage all subscriptions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsHigh122Free2021-11-26Windows PowerShell Clears Console History via Clear-History
Flags PowerShell attempts to clear or delete console/PSReadline command history to hinder command forensics.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptHigh60Free2021-11-25Windows: Rundll32 Loading shell32.dll via Control_RunDLL from User/Temp Paths
Alerts on rundll32.exe loading shell32.dll with Control_RunDLL from AppData/Temp/user paths.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2021-11-24Windows CertReq -Post Download Attempt via HTTP
Flags certreq.exe executions using -Post -config and HTTP content retrieval indicators.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh349Free2021-11-24Windows PsExec/PAExec Command-Line Flags Escalating to LOCAL SYSTEM
Flags in PsExec/PAExec command lines requesting LOCAL SYSTEM execution are matched via process creation command-line telemetry.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2021-11-23Windows MSIInstaller EventID 1033 PoC File Takeover String Match (InstallerFileTakeOver/CVE-2021-41379)
Alert on Windows MSI installer EventID 1033 with event data containing 'test pkg', consistent with PoC activity for CVE-2021-41379.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh197Free2021-11-22Windows Shell/Scripting Tool File Write to Suspicious Directories
Alert on file writes by common Windows shells/scripting tools to C:\PerfLogs, C:\Users\Public, or C:\Windows\Temp.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh143Free2021-11-20Windows Registry New File Association via exefile Handler (Classes\*.exefile)
Alerts on Windows registry changes creating a new file association that points to the exefile handler.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_setHigh103Free2021-11-19Windows MSExchange Management events indicating likely MS Exchange RCE CVE-2021-42321 exploitation
Flags Exchange management events showing Get-App cmdlet failures and unhandled InvalidCastException during CVE-2021-42321 RCE attempts.
Florian Roth (Nextron Systems), @testanull, Huntrule TeamWindowsmsexchange-managementHigh111Free2021-11-18Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)
Flags ADCS template load/update events (4898/4899) when risky EKU OIDs and enrollee-supplied subject are present.
Orlinum , BlueDefenZer, Huntrule TeamWindowssecurityHigh469Free2021-11-17Sitecore Pre-Auth RCE (CVE-2021-42237) exploitation attempts via Report.ashx POST
Alerts on successful HTTP POST traffic targeting Sitecore Reporting Report.ashx associated with CVE-2021-42237.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh113Free2021-11-17Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Alerts on scheduled task storage writes under System32\Tasks originating from suspicious process locations.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh141Free2021-11-16Windows: reg.exe Adds BitLocker Policy Registry Values
Flags reg.exe registry additions targeting BitLocker policy keys associated with configuration changes.
frack113, Huntrule TeamWindowsprocess_creationHigh396Free2021-11-15Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh257Free2021-11-15