Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
Wojciech Lesicki, Huntrule TeamWindowsregistry_setHigh233Free2021-06-29Pulse Connect Secure web exploitation attempts for CVE-2021-22893
Detects web requests to Pulse Connect Secure with URI query patterns consistent with CVE-2021-22893 exploitation attempts.
Sittikorn S, Huntrule Team—webserverHigh486Free2021-06-29AWS CloudTrail: Security Hub findings evasion via finding updates or deletions
Identifies Security Hub finding and insight modifications (update or delete) that may impair detection results.
Sittikorn S, Huntrule TeamAwscloudtrailHigh202Free2021-06-28Windows Process Creation: WMIC.exe ActiveScriptEventConsumer Creation Attempt
Alerts on WMIC.exe command lines attempting to create an ActiveScriptEventConsumer for event-driven script execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh504Free2021-06-25Zeek x509: Default Cobalt Strike certificate serial observed in HTTPS traffic
Flags Zeek x509 certificates used in HTTPS when the certificate serial matches a known default Cobalt Strike value.
Bhabesh Raj, Huntrule TeamZeekx509High192Free2021-06-23Windows: Detect execution of renamed megasync.exe (original MegaSync) via process creation
Flags process launches where megasync.exe appears under a renamed or nonstandard execution context based on process creation fields.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh4610Free2021-06-22Windows: Suspicious Child Process Spawned by scrcons.exe (Script Event Consumer)
Alerts on rare child processes spawned by scrcons.exe, which may indicate abuse of Script Event Consumer for execution.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh393Free2021-06-21Windows Registry: New TaskCache entry created by unusual process image
Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.
Syed Hasan (@syedhasan009), Huntrule TeamWindowsregistry_setHigh212Free2021-06-18Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.
MSTIC, FPT.EagleEye, Huntrule TeamWindowsprocess_creationHigh193Free2021-06-15Windows Registry Set—Custom Outlook Today Page for Persistence
Flags registry writes that configure a custom Outlook Today URL using Outlook Today registry values.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh339Free2021-06-10Windows Persistence Attempt Using Outlook.exe to Create Outlook Forms Cache
Flags Outlook (outlook.exe) form file activity targeting local FORMS directories often used for persistence.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsfile_eventHigh201Free2021-06-10Windows Registry Changes for Outlook WebView Home Page URL Persistence
Alerts on Windows registry modifications affecting Outlook WebView home page URL settings.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh474Free2021-06-09Windows Registry: Microsoft Office Protected View Disabled via Security Policy Keys
Flags Windows registry updates that disable Microsoft Office Protected View for attachments, internet files, UNC paths, or unsafe locations.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh252Free2021-06-08Windows MSExchange: Failed Transport Agent Installation (Install-TransportAgent)
Alerts on EventID 6 Exchange management events that include "Install-TransportAgent", indicating a failed Transport Agent installation attempt.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh4210Free2021-06-08Windows AMSI Provider Registry Key Deletion (HKLM\Software\Microsoft\AMSI)
Alerts on deletion of AMSI provider registry key entries under HKLM\Software\Microsoft\AMSI, potentially indicating AMSI inspection impairment.
frack113, Huntrule TeamWindowsregistry_deleteHigh172Free2021-06-07