Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux: Process executing update-ca-certificates or update-ca-trust
Detects Linux executions of update-ca-certificates or update-ca-trust that install new trusted root certificates.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationLow172Free2020-10-05Windows Process Creation: WSL (wsl.exe) Used for Arbitrary Command Execution
Alerts when wsl.exe is launched with execution-focused options that may enable arbitrary Linux/Windows command execution.
oscd.community, Zach Stanford @svch0st, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2020-10-05Windows Process Proxying: explorer.exe Spawned from cmd.exe or PowerShell
Flags cmd.exe/powershell.exe launching explorer.exe, indicating possible proxy-based execution on Windows.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Huntrule TeamWindowsprocess_creationLow100Free2020-10-05Windows: Manual persistence attempt using schtasks to run Microsoft Compatibility Appraiser
Alerts when schtasks runs "Microsoft Compatibility Appraiser" via Application Experience, consistent with persistence abuse.
Sreeman, Huntrule TeamWindowsprocess_creationMedium126Free2020-09-29Windows service configuration tampering via sc/reg with payload execution paths
Looks for sc/reg command-line activity that updates Windows service ImagePath or FailureCommand to run attacker-controlled payloads.
Sreeman, Huntrule TeamWindowsprocess_creationMedium217Free2020-09-29Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)
Flags HKCU DelegateExecute registry changes for COM hijack style persistence under the Folder shell open command.
Omkar Gudhate, Huntrule TeamWindowsregistry_setHigh101Free2020-09-27Windows VirtualBox Driver Registration or VM Startup via Process Command Line
Alerts on Windows processes whose command lines reference VirtualBox driver registration or VM start/control actions.
Janantha Marasinghe, Huntrule TeamWindowsprocess_creationLow186Free2020-09-26Detect Wannacry killswitch DNS queries to hardcoded domains
Flags DNS lookups for known WannaCry killswitch domain strings and variants.
Mike Wade, Huntrule TeamNetworkdnsHigh131Free2020-09-16Windows NetLogon Secure Channel Connection Allowed for Vulnerable Client
Alerts on Windows NetLogon ETW events indicating an allowed secure channel connection (Event ID 5829).
NVISO, Huntrule TeamWindowssystemHigh92Free2020-09-15Windows Defender Windefend AMSI Detection (Event ID 1116)
Flags Windows Defender AMSI detections via windefend Event ID 1116 with SourceName set to AMSI.
Bhabesh Raj, Huntrule TeamWindowswindefendHigh60Free2020-09-14Windows Registry Set: .NET COR/CORECLR Profiling Environment Variables Enabled
Alerts on registry writes enabling .NET CLR/CORECLR profiling variables like COR_ENABLE_PROFILING and COR_PROFILER.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Jimmy Bayne (@bohops), Huntrule TeamWindowsregistry_setMedium427Free2020-09-10Windows Process Creation: MpCmdRun.EXE Used to Download Files via DownloadFile url
Alerts when MpCmdRun.exe is executed with DownloadFile and url, indicating Defender utility file download behavior.
Matthew Matchen, Huntrule TeamWindowsprocess_creationHigh181Free2020-09-04WMI scrcons.exe Loading Script and WMI DLLs via Image Load (Windows)
Alerts when scrcons.exe loads vbscript/wbem/WMI script DLLs, suggesting WMI ActiveScriptEventConsumer activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium103Free2020-09-02Windows Security 4624 Logon for scrcons.exe Indicating Remote WMI ActiveScriptEventConsumers
Flags remote network logons involving scrcons.exe that may indicate WMI ActiveScriptEventConsumers activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityMedium70Free2020-09-02Windows Process Creation Indicators for Snatch Ransomware Word Document Droppers
Alerts on Windows process command lines showing instant safe-mode shutdown/reboot and stopping SuperBackupMan service.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2020-08-26