Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Desktop Image Downloader Targeting Lock Screen Images with Suspicious File Types
Alerts on desktopimgdownldr-style lock screen image target writes to non-system paths with suspicious filename characteristics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh253Free2020-07-03Apache Guacamole Linux: Two-User Session Presence Anomaly
Flags Guacamole sessions on Linux when telemetry indicates two users are present, suggesting anomalous or suspicious session activity.
Florian Roth (Nextron Systems), Huntrule TeamLinuxguacamoleHigh306Free2020-07-03Windows: Detect curl.exe upload/data flags indicative of possible exfiltration
Detects curl.exe executions with upload/form/data flags on Windows that may indicate potential data exfiltration, excluding localhost targets.
Florian Roth (Nextron Systems), Cedric MAURUGEON (Update), Huntrule TeamWindowsprocess_creationMedium40Free2020-07-03Windows Registry Printer Driver Installations with Empty Manufacturer Field
Alerts on Windows registry printer driver environment updates where Manufacturer is set to empty.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh309Free2020-07-01PowerShell Classic bXOR Operator Usage in Command Line
Identifies PowerShell classic executions from ConsoleHost using the -bxor operator in the command line.
Teymur Kheirkhabarov, Harish Segar, Huntrule TeamWindowsps_classic_startLow70Free2020-06-29Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Alerts on AppLocker event IDs showing blocked execution of apps, scripts, DLLs, MSI, or packaged apps.
Pushkarev Dmitry, Huntrule TeamWindowsapplockerMedium371Free2020-06-28Windows Security Log: Denied Remote Desktop Logon (Event ID 4825)
Flags Windows denied RDP connection attempts from users lacking permission to log on remotely (Event ID 4825).
Pushkarev Dmitry, Huntrule TeamWindowssecurityMedium433Free2020-06-27Windows Registry Event Triggered by RedMimicry Winnti Playbook (HTMLHelp\data)
Alerts on Windows registry events targeting HKLM\SOFTWARE\Microsoft\HTMLHelp\data associated with the RedMimicry Winnti playbook.
Alexander Rausch, Huntrule TeamWindowsregistry_eventHigh122Free2020-06-24Windows process execution matching Winnti RedMimicry playbook (rundll32/cmd with temp batch and gthread/sigcmm DLLs)
Flags rundll32.exe/cmd.exe launches with Winnti-specific DLL and temp batch indicators.
Alexander Rausch, Huntrule TeamWindowsprocess_creationHigh40Free2020-06-24Suspicious WSMAN COM Provider Usage Without PowerShell Host (Windows)
Alerts on WSMAN COM provider activity where the host application is not PowerShell.exe in PowerShell Classic logs.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspowershell-classicMedium143Free2020-06-24Windows File Drops Matching Winnti Dropper Artifacts (gthread/sigcmm DLLs, tmp.bat)
Detects Windows file drops of specific DLLs and a Windows Temp batch filename pattern associated with a Winnti dropper scenario.
Alexander Rausch, Huntrule TeamWindowsfile_eventHigh139Free2020-06-24Windows Process Creation: Detect reg.exe Add Control Panel CPL Items
Alerts on reg.exe adding Control Panel CPL items via CurrentVersion\Control Panel\CPLs, a common vector for stealthy execution/persistence.
Kyaw Min Thein, Furkan Caliskan (@caliskanfurkan_), Huntrule TeamWindowsprocess_creationHigh71Free2020-06-22Windows Process Creation: IE Security Registry Values Disabled via Command Line
Alerts on Windows command lines that set IE hardening-related registry values to disable security features.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3610Free2020-06-19Linux Remote File Copy via scp, rsync, or sftp
Flags Linux command lines using scp/rsync/sftp with remote-target style arguments containing “@” and “:”.
Ömer Günal, Huntrule TeamLinux—Low142Free2020-06-18Windows Registry Modification via Process Creation Command Lines Indicative of Ke3chang/TidePool
Alerts on Windows process command lines that set IE hardening and related Internet Explorer registry properties consistent with Ke3chang/TidePool.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh63Free2020-06-18