Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux System Network Discovery via Firewall/Network Tools
Alerts on Linux process activity running common network/firewall tools and DNS discovery indicators.
Ömer Günal and remotephone, oscd.community, Huntrule TeamLinuxprocess_creationInformational123Free2020-10-06Linux Cron Abuse via crontab Executed with /tmp/ File Paths
Identifies crontab usage on Linux where /tmp/ is present in the command line, suggesting cron job staging for persistence or execution.
Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationMedium131Free2020-10-06Linux at/atd Process Execution via /at or /atd
Flags execution of /at or /atd on Linux, indicating scheduled job creation via at scheduling utilities.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationLow4910Free2020-10-06Windows PowerShell Process Creation with Unusually Long Command Lines (1000+ chars)
Flags PowerShell executions on Windows when the CommandLine is 1000+ characters long.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_creationLow100Free2020-10-06PowerShell Access to LSASS on Windows Suggesting Credential Dumping
Alerts when PowerShell (powershell.exe/pwsh.exe) accesses lsass.exe, indicating potential credential dumping.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_accessMedium90Free2020-10-06PowerShell Remote Thread Creation (Windows CreateRemoteThread)
Alerts when PowerShell creates a remote thread in another process, excluding CompatTelRunner.exe activity.
Nikita Nazarov, oscd.community, Huntrule TeamWindowscreate_remote_threadMedium60Free2020-10-06Linux process discovery via common process listing and monitoring tools
Flags Linux execution of common tools used to enumerate running processes.
Ömer Günal, oscd.community, CheraaghiMilad, Huntrule TeamLinuxprocess_creationLow80Free2020-10-06Non-privileged reg.exe or PowerShell registry service configuration changes on Windows
Flags non-admin reg.exe or PowerShell activity targeting service registry configuration paths on Windows.
Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh419Free2020-10-05Windows Print Executable Misuse via print.exe Command-Line
Flags suspicious print.exe invocations using /D and .exe, excluding command lines that explicitly contain print.exe.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Huntrule TeamWindowsprocess_creationMedium264Free2020-10-05Windows: Rundll32 LaunchApplication via pcwutl.dll
Flags rundll32.exe using pcwutl.dll to invoke LaunchApplication.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium143Free2020-10-05Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Alerts when Windows process command lines include Hydra -u/-p parameters with USER/PASS placeholders.
Vasiliy Burov, Huntrule TeamWindowsprocess_creationHigh121Free2020-10-05Windows findstr.exe Subfolder and Case-Insensitive Search Flags
Alerts on findstr.exe executions that include both -s (subfolders) and -i (case-insensitive) flags.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow132Free2020-10-05Windows: SyncAppvPublishingServer.exe execution via PowerShell script block content
Flags PowerShell script blocks that reference SyncAppvPublishingServer.exe, indicating possible execution via a PowerShell-restricted workflow.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_scriptMedium131Free2020-10-05Windows SyncAppvPublishingServer Execution Triggering PowerShell Module Context
Alerts when SyncAppvPublishingServer.exe appears in PowerShell module ContextInfo on Windows.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_moduleMedium455Free2020-10-05Windows Security: Suspicious Remote Logon Using Explicit Credentials via Command-Line Tools
Flags EventID 4648 remote logons initiated by cmd/PowerShell/winrs/wmic/net/reg-style processes using explicit credentials.
oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton, Huntrule TeamWindowssecurityMedium61Free2020-10-05