Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows DCOM InternetExplorer.Application iertutil.dll DLL Hijack Suspicion
Alerts when System writes iertutil.dll in the DCOM InternetExplorer.Application path, consistent with potential DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, Huntrule TeamWindowsfile_eventCritical183Free2020-10-12Windows System: Service Control Manager runs command with obfuscated PowerShell keywords via set and stdin
Alerts on service creation where ImagePath includes obfuscation-like command chaining with environment/invoke/input strings.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh70Free2020-10-12Windows Security Log: Network Write of wbemcomn.dll in System32\wbem for WMI DLL Hijack (T1047)
Flags remote creation of wbemcomn.dll in System32\wbem associated with WMI DLL hijack activity.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityHigh4110Free2020-10-12Windows Security Event 4697: Obfuscated PowerShell Invocation Through Stdin
Alerts on Service creation events where the service command line includes stdin-style PowerShell obfuscation indicators.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh101Free2020-10-12Windows Security: Remote DCOM IE DLL Hijack via iertutil.dll in Internet Explorer path
Flags network file writes of iertutil.dll under IE’s Program Files path associated with potential DCOM DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityHigh155Free2020-10-12Windows Registry Screensaver Path Value Modified (SCRNSAVE.EXE)
Alerts on registry changes to the SCRNSAVE.EXE screensaver binary path under HKCU.
Bartlomiej Czyz @bczyz1, oscd.community, Huntrule TeamWindowsregistry_eventMedium131Free2020-10-11Windows PowerShell Command Line Encoded-Content Indicators via Type Conversion and String Building
Detects PowerShell command lines containing type-conversion and join/split character assembly indicators consistent with encoded content handling.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationLow463Free2020-10-11Windows Process Creation: Detect Reversed PowerShell Command Tokens in CommandLine
Alerts on suspicious reversed token usage in PowerShell command lines on Windows, excluding -EncodedCommand / -enc.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationHigh257Free2020-10-11PowerShell ConvertTo-SecureString Cmdlet Execution from Command Line (Windows)
Alerts when PowerShell is launched with a command line containing ConvertTo-SecureString, a credential-related cmdlet uncommon in normal execution.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton, Huntrule TeamWindowsprocess_creationMedium70Free2020-10-11Windows msbuild.exe Network Connections to Ports 80/443
Alerts on initiated outbound 80/443 connections from msbuild.exe on Windows.
Kiran kumar s, oscd.community, Huntrule TeamWindowsnetwork_connectionHigh81Free2020-10-11macOS Local Group Enumeration via dscacheutil, cat /etc/group, or dscl
Flags macOS process executions that enumerate local system groups using dscacheutil, cat, or dscl commands.
Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule TeamMacosprocess_creationInformational304Free2020-10-11macOS Host Indicator Removal via rm/unlink/shred of Local Log Paths
Flags macOS rm/unlink/shred commands targeting /var/log or ~/Library/Logs to remove local log evidence.
remotephone, oscd.community, Huntrule TeamMacosprocess_creationMedium2810Free2020-10-11Linux Local Groups Discovery via /groups or /etc/group File Enumeration
Detects Linux commands and utilities used to enumerate local groups and read /etc/group.
Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationLow359Free2020-10-11PowerShell Execution via sqlps.exe (Windows Process Creation)
Flags sqlps.exe process launches consistent with PowerShell execution on Windows, excluding common sqlagent.exe-driven cases.
Agro (@agro_sev) oscd.community, Huntrule TeamWindowsprocess_creationMedium383Free2020-10-10PowerShell Root Certificate Added via LocalMachine\Root Path
Flags PowerShell scripts that move and import certificates into the local machine root store (Cert:\LocalMachine\Root).
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsps_scriptMedium102Free2020-10-10