Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process Creation: Microsoft QuickAssist.exe Execution
Alerts on execution of QuickAssist.exe by matching the process image ending with \QuickAssist.exe.
Muhammad Faisal (@faisalusuf), Huntrule TeamWindowsprocess_creationLow121Free2024-12-19Windows DNS Queries Initiated by QuickAssist.exe to remoteassistance.support.services.microsoft.com
Alerts when QuickAssist.exe performs DNS lookups for the Microsoft Quick Assist remote session endpoint.
Muhammad Faisal (@faisalusuf), Huntrule TeamWindowsdns_queryLow449Free2024-12-19AWS CloudTrail: CreateFunctionUrlConfig Indicates Lambda Function URL Added
Flags when a Lambda Function URL configuration is created via the CreateFunctionUrlConfig API call.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium142Free2024-12-19AWS EC2 ImportKeyPair Activity Monitoring (CloudTrail)
Flags CloudTrail EC2 ImportKeyPair events that may indicate newly imported SSH key access setup.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium91Free2024-12-19AWS IAM SAML Provider Deletion via CloudTrail
Alerts on successful CloudTrail events where an AWS SAML provider is deleted, signaling potential disruption of admin/security access.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium1710Free2024-12-19Windows Process Creation: Execution of vbc.exe Spawned from more.com
Alerts when more.com starts vbc.exe on Windows, matching a known stealer execution pattern.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationHigh101Free2024-12-19Windows File Creation to Roaming AppData DataLogs.conf and RAT-Client Names
Alerts on creation of specific RAT client config files under AppData\Roaming on Windows.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_eventHigh277Free2024-12-19Windows Process Creation: Suspicious cmd.exe Launch with Encoded PowerShell from Cleo Suite
Alerts on cmd.exe launching PowerShell encoded commands from Cleo javaw.exe components with .Download.
Tanner Filip, Austin Worline, Chad Hudson, Matt Anderson, Huntrule TeamWindowsprocess_creationHigh307Free2024-12-09AWS CloudTrail: RDS Cluster Modification or Deletion (ModifyDBCluster/DeleteDBCluster)
Detects CloudTrail ModifyDBCluster or DeleteDBCluster actions on AWS RDS clusters.
Ivan Saakov, Huntrule TeamAwscloudtrailHigh192Free2024-12-06Windows Setup16.EXE Execution Triggered by Custom .LST File
Flags Windows Setup16.EXE being invoked with ' -m ' from its system parent process, potentially tied to custom .lst-driven execution.
frack113, Huntrule TeamWindowsprocess_creationMedium163Free2024-12-01Windows Suspicious ShellExec_RunDLL via SHELL32.DLL Ordinal in Parent Command Line
Alert on Windows process starts where parent command line invokes SHELL32.DLL ShellExec_RunDLL using a matched ordinal and spawns suspicious binaries.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh269Free2024-12-01Windows File Event: Detect RTLO Filename Extension Spoofing
Flags Windows filenames containing U+202E plus reversed extension strings that indicate potential extension spoofing.
Jonathan Peters (Nextron Systems), Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh172Free2024-11-17Windows Network Connections to azurefd.net Excluding Common Browsers and Known Front Door Hostnames
Flags Windows connections to azurefd.net that aren’t from common browsers/search or known benign Azure Front Door domains.
Isaac Dunham, Huntrule TeamWindowsnetwork_connectionMedium70Free2024-11-07Windows Registry RunMRU PowerShell or WMIC Execution Command Indicators
Alerts on RunMRU registry entries showing PowerShell (encoding/invocation) or WMIC shadowcopy/process call usage.
Ahmed Farouk, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh161Free2024-11-01Windows Command Execution via Run Dialog (RunMRU) Registry Entries
Flags suspicious Run dialog command entries by matching RunMRU registry key updates on Windows.
Ahmed Farouk, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setLow90Free2024-11-01