Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux: Detect dd and truncate used to pad binaries and alter file contents
Flags Linux process executions of dd and truncate consistent with padding binaries to alter on-disk representation.
Igor Fits, oscd.community, Huntrule TeamLinuxauditdHigh101Free2020-10-13Windows Proxy Execution via wuauclt.exe (UpdateDeploymentProvider/RunHandlerComServer)
Alerts when wuauclt.exe is executed with UpdateDeploymentProvider/RunHandlerComServer-related parameters indicative of proxy execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Florian Roth (Nextron Systems), Sreeman, FPT.EagleEye Team, Huntrule TeamWindowsprocess_creationHigh238Free2020-10-12Windows WMIC process creation with suspicious command execution
Alerts on WMIC spawning new processes with command-line indicators of common execution/payload binaries on Windows.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2020-10-12Windows regini.exe Used to Modify Registry via Alternate Data Streams (ADS)
Alert on regini.exe process executions whose command line contains an ADS-style colon pattern used for registry modification.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh189Free2020-10-12Windows: regedit.exe imports .reg via an alternate data stream (ADS)
Alerts when regedit.exe is used to import a .reg file using an alternate data stream pattern in the command line.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2020-10-12Windows Regedit Exports Registry Hives to Files
Flags regedit.exe command lines exporting SYSTEM/SAM/SECURITY hives from HKLM to files.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh322Free2020-10-12Windows Process Creation: PowerShell or sc.exe Disabling Windows Defender Behavior Monitoring
Detects PowerShell flags or sc.exe service actions that disable WinDefend monitoring on Windows.
ok @securonix invrep-de, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh144Free2020-10-12Windows Indirect Command Execution via Program Compatibility Assistant pcwrun.exe
Alerts on child processes spawned by pcwrun.exe, indicating indirect command execution via Program Compatibility Assistant.
A. Sungurov , oscd.community, Huntrule TeamWindowsprocess_creationLow151Free2020-10-12Detect Obfuscated PowerShell Command Invocation via Stdin on Windows
Flags PowerShell-like command-line patterns indicating obfuscated execution using stdin or input substitution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh293Free2020-10-12Windows Process Creation: AtBroker.exe Launching Assistive Technology Apps
Alerts on Windows process starts of AtBroker.exe with "start" that don’t match known built-in accessibility parameters.
Mateusz Wydra, oscd.community, Huntrule TeamWindowsprocess_creationMedium111Free2020-10-12PowerShell Obfuscation Delivered via Stdin Using Set-and-Invoke Pattern
Detects obfuscated PowerShell script blocks that use chained stdin/environment/input patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh4510Free2020-10-12PowerShell Module: Obfuscated Script Execution via Stdin Pattern
Detects obfuscated PowerShell module payloads using chained set and stdin/input invoke patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh366Free2020-10-12Windows WMIPRVSE DLL Hijack via Network-Created wbemcomn.dll in System32\wbem
Flags wmiprvse.exe loading wbemcomn.dll from the System32\wbem directory, consistent with a WMI DLL hijack.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh125Free2020-10-12Windows DCOM InternetExplorer.Application DLL Hijack via iertutil.dll Image Load
Alerts when iexplore.exe loads iertutil.dll from an Internet Explorer path, indicating possible DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, Huntrule TeamWindowsimage_loadCritical183Free2020-10-12Windows WMI DLL Hijack via Network-placed wbemcomn.dll in System32\wbem
Alerts when System creates wbemcomn.dll in C:\Windows\System32\wbem\, consistent with WMI DLL hijack file staging.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventCritical359Free2020-10-12