Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Zeek: Public RDP Connections from Non-Private IPv4/IPv6 Ranges
Alert on Zeek-observed RDP connections originating from non-excluded IP ranges, suggesting external accessibility.
Josh Brower @DefensiveDepth, Huntrule TeamZeekrdpHigh225Free2020-08-22Windows Process Creation: Mouse Lock Execution with “Misc314” Indicator
Alerts on Windows executions of Mouse Lock where Company includes “Misc314” and CommandLine contains “Mouse Lock_”.
Cian Heasley, Huntrule TeamWindowsprocess_creationMedium101Free2020-08-13Windows Defender windefend Event 1013: Malware detection history deletion
Alerts when Windows Defender deletes its malware/PUA detection history via windefend Event ID 1013.
Cian Heasley, Huntrule TeamWindowswindefendInformational298Free2020-08-13Windows Security Event 5145: SMB Write Access to Admin Share (C$)
Flags non-machine accounts writing via SMB to the C$ administrative share using Security EventID 5145.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh132Free2020-08-06Webserver logs: Webshell ReGeorg indicators in POST URI query with null Referer/User-Agent
Flags HTTP POST requests with null referer/user-agent and ReGeorg-like URI query parameters in web logs.
Cian Heasley, Huntrule TeamWebwebserverHigh161Free2020-08-04Windows Process Creation: Winnti Pipemon setup* Command-Line Parameters
Alerts on Windows processes launching Pipemon-style setup.exe command lines with specific -p or -x:n flags.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationCritical224Free2020-07-30Windows TAIDOOR RAT DLL Load via rundll32 Command Line
Detects Windows process creation command lines consistent with TAIDOOR RAT DLL loading through rundll32.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2020-07-30Windows windefend Event ID 5012: Windows Defender virus scanning disabled
Flags when Windows Defender disables virus scanning via windefend Event ID 5012.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh92Free2020-07-28Windows windefend: Windows Defender threat detection and mitigation events
Alerts on windefend events indicating Windows Defender malware detection and potential remediation activity.
Ján Trenčanský, Huntrule TeamWindowswindefendHigh133Free2020-07-28Windows windefend EventID 5001: Windows Defender real-time protection disabled
Flags windefend Event ID 5001 indicating Windows Defender real-time protection was disabled.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh122Free2020-07-28Windows windefend: Microsoft Defender malware and PUA scanning disabled (Event ID 5010)
Flags Windows Defender disabling malware and PUA scanning using Windefend Event ID 5010.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh123Free2020-07-28Windows Defender antimalware grace period expired (Event ID 5101)
Alerts when Windows Defender signals its antimalware grace period expired via windefend Event ID 5101.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh91Free2020-07-28Windows Service Control Manager: Windows Defender Threat Protection Disabled
Flags Service Control Manager events where the Windows Defender Threat Protection (Defender Antivirus) service is stopped.
Ján Trenčanský, frack113, Huntrule TeamWindowssystemMedium458Free2020-07-28Windows webserver-spawned recon commands probing scripting tool help (perl/python/wget)
Flags webserver child processes running perl/python/python3/wget help commands to probe available tooling on the host.
Cian Heasley, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2020-07-22Windows DLL Load Indicates Potential Azure Browser SSO OAuth Token Request Abuse
Alerts on MicrosoftAccountTokenProvider.dll loads on Windows, with process-based exclusions, as a signal for potential Azure Browser SSO token activity.
Den Iuzvyk, Huntrule TeamWindowsimage_loadLow151Free2020-07-15