Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,291 rules
Windows Security Event 5145: SMB Write Access to Admin Share (C$)
Flags non-machine accounts writing via SMB to the C$ administrative share using Security EventID 5145.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh152Free2020-08-06Webserver logs: Webshell ReGeorg indicators in POST URI query with null Referer/User-Agent
Flags HTTP POST requests with null referer/user-agent and ReGeorg-like URI query parameters in web logs.
Cian Heasley, Huntrule TeamWebwebserverHigh161Free2020-08-04Windows TAIDOOR RAT DLL Load via rundll32 Command Line
Detects Windows process creation command lines consistent with TAIDOOR RAT DLL loading through rundll32.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh183Free2020-07-30Windows windefend Event ID 5012: Windows Defender virus scanning disabled
Flags when Windows Defender disables virus scanning via windefend Event ID 5012.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh132Free2020-07-28Windows windefend: Windows Defender threat detection and mitigation events
Alerts on windefend events indicating Windows Defender malware detection and potential remediation activity.
Ján Trenčanský, Huntrule TeamWindowswindefendHigh183Free2020-07-28Windows windefend EventID 5001: Windows Defender real-time protection disabled
Flags windefend Event ID 5001 indicating Windows Defender real-time protection was disabled.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh172Free2020-07-28Windows windefend: Microsoft Defender malware and PUA scanning disabled (Event ID 5010)
Flags Windows Defender disabling malware and PUA scanning using Windefend Event ID 5010.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh163Free2020-07-28Windows Defender antimalware grace period expired (Event ID 5101)
Alerts when Windows Defender signals its antimalware grace period expired via windefend Event ID 5101.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh101Free2020-07-28Windows webserver-spawned recon commands probing scripting tool help (perl/python/wget)
Flags webserver child processes running perl/python/python3/wget help commands to probe available tooling on the host.
Cian Heasley, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2020-07-22Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
Bhabesh Raj, Huntrule TeamWindowswindefendHigh133Free2020-07-14Windows Sysmon Operational Channel Reference Deleted via Security Event
Detects Security log events showing Sysmon Operational channel being disabled via channel reference deletion-like changes.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh131Free2020-07-14Empire C2 Proxy Requests with Specific User-Agent and POSTed PHP URIs
Flags proxy HTTP POSTs using an Empire-like user agent to specific admin/login PHP endpoints.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh355Free2020-07-13Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2020-07-09Windows Process Execution of DIT Snapshot Viewer (ditsnap.exe)
Alerts on execution of the DIT snapshot viewer tool ditsnap.exe on Windows.
Furkan Caliskan (@caliskanfurkan_), Huntrule TeamWindowsprocess_creationHigh297Free2020-07-04Windows desktopimgdownldr Suspicious URL and Registry Modification via Command Line
Flags desktopimgdownldr command lines indicating potential external file download or personalization registry deletion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh468Free2020-07-03