Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,297 rules
Windows Process Creation: Command-Line Indicators of Crypto Mining
Alerts on Windows processes with command-line arguments matching common crypto miner pool and configuration indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2021-10-26Windows Network Connections to Known Crypto Mining Pools
Flags Windows hosts making outbound connections to known cryptocurrency mining pool domains.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh398Free2021-10-26Linux Process Creation Crypto Miner Command-Line Indicators
Alerts on Linux process executions with command-line strings typical of crypto mining pools, stratum endpoints, and miner options.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh147Free2021-10-26Linux Process Network Connections to Crypto Mining Pool Hosts
Flags Linux outbound connections to known Monero mining pool domains.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionHigh371Free2021-10-26PowerShell Creating Startup .lnk Shortcut Persistence (Windows File Events)
Detects PowerShell writing .lnk files into the Windows Startup folder, a common persistence mechanism.
Christopher Peacock '@securepeacock', SCYTHE, Huntrule TeamWindowsfile_eventHigh1810Free2021-10-24DNS Queries for Monero Mining Pool Domains
Alerts on DNS queries to known Monero mining pool domains that may indicate cryptomining activity.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsHigh395Free2021-10-24Windows Process Execution via WorkFolders.exe Launching control.exe
Alerts when WorkFolders.exe spawns a non-standard control.exe instance on Windows.
Maxime Thiebaut (@0xThiebaut), Huntrule TeamWindowsprocess_creationHigh113Free2021-10-21Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
Detects stordiag.exe spawning schtasks.exe, systeminfo.exe, or fltmc.exe to support system discovery or config actions on Windows.
Austin Songer (@austinsonger), Huntrule TeamWindowsprocess_creationHigh132Free2021-10-21Windows Registry: Clearing RDP Client Connection History via MRU and Server Keys Deletion
Flags registry deletions that remove Windows RDP client connection history from Terminal Server Client MRU and Servers keys.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh457Free2021-10-19Linux Process Creation Webshell Tooling: Web Server Child Processes Running System Commands
Detects web server processes spawning Linux command-line tools commonly used for host discovery or persistence.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh203Free2021-10-15Linux Syslog Clearing or Removal Using System Utilities
Alert on Linux commands that clear, delete, truncate, or redirect /var/log/syslog or rotate/vacuum journald logs.
Max Altgelt (Nextron Systems), Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamLinuxprocess_creationHigh244Free2021-10-15Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
bohops, Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh153Free2021-10-08Windows Registry Writes for NetWire-Related Keys
Flags newly added Windows registry keys with paths containing \\software\\NetWire, consistent with potential NetWire-related persistence.
Christopher Peacock, Huntrule TeamWindowsregistry_addHigh163Free2021-10-07Apache HTTP Server Web Path Traversal Attempt via Encoded Traversal Sequences (CVE-2021-41773)
Alerts on Apache requests with encoded traversal strings that return 200/301, consistent with CVE-2021-41773 probing.
daffainfo, Florian Roth, Huntrule Team—webserverHigh151Free2021-10-05Windows Prefetch File Deletion via .pf File Removal
Flags deletion of .pf files in \\Windows\\Prefetch, a possible attempt to remove execution artifacts.
Cedric MAURUGEON, Huntrule TeamWindowsfile_deleteHigh174Free2021-09-29