Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Windows: WinRM Service Process Spawning Command-Line and Scripting Utilities
Flags suspicious child shells and admin utilities spawned by the WinRM host process (wsmprovhost.exe) on Windows.
Andreas Hunkeler (@Karneades), Markus Neis, Huntrule TeamWindowsprocess_creationHigh293Free2021-05-20PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh2310Free2021-05-18Windows Process Command Lines Indicating ngrok.exe Tunnel Setup
Detects Windows executions of ngrok.exe with TCP/HTTP tunneling and authtoken/start-all YAML configuration patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh221Free2021-05-14Windows: Detect Rclone command execution with exfiltration-oriented flags
Identifies likely rclone.exe exfiltration activity on Windows by matching command-line flags and rclone executable characteristics.
Bhabesh Raj, Sittikorn S, Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsprocess_creationHigh173Free2021-05-10Windows whoami.exe Privilege Enumeration Using /priv Flag
Alerts on whoami.exe runs with /priv or -priv to enumerate current user privileges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2021-05-05Linux Code Injection via ld.so Preload File (/etc/ld.so.preload)
Alerts on references to /etc/ld.so.preload, indicating possible dynamic-library injection persistence on Linux.
Christian Burkard (Nextron Systems), Huntrule TeamLinux—High387Free2021-05-05Windows Pingback backdoor via ICMP C2 using updata.exe command-line parameters
Flags Windows process creation where updata.exe spawns msdtc config start auto commands consistent with Pingback backdoor.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh102Free2021-05-05Windows DLL Loading of C:\Windows\oci.dll by msdtc.exe
Flags msdtc.exe loading C:\Windows\oci.dll, consistent with Pingback backdoor DLL loading behavior.
Bhabesh Raj, Huntrule TeamWindowsimage_loadHigh478Free2021-05-05Windows File Indicator for Pingback Backdoor updata.exe Writing oci.dll
Alerts on updata.exe creating or modifying C:\Windows\oci.dll as a Pingback backdoor file indicator.
Bhabesh Raj, Huntrule TeamWindowsfile_eventHigh254Free2021-05-05Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh426Free2021-05-03Windows Security: Hidden Local User Account Creation (Event ID 4720)
Alerts on Windows 4720 local user creation for hidden accounts (username ending with '$'), excluding 'HomeGroupUser$'.
Christian Burkard (Nextron Systems), Huntrule TeamWindowssecurityHigh90Free2021-05-03Windows Process Access to svchost.exe with Credential Dumping Access Rights
Alerts on attempts to read svchost.exe memory consistent with credential dumping, excluding known benign callers.
Florent Labouyrie, Huntrule TeamWindowsprocess_accessHigh343Free2021-04-30Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh457Free2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh142Free2021-04-23Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Flags HybridConnectionManager-initiated DNS queries to servicebus.windows.net on Windows.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsdns_queryHigh136Free2021-04-12