Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,290 rules
Windows Desktop Image Downloader Targeting Lock Screen Images with Suspicious File Types
Alerts on desktopimgdownldr-style lock screen image target writes to non-system paths with suspicious filename characteristics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh273Free2020-07-03Apache Guacamole Linux: Two-User Session Presence Anomaly
Flags Guacamole sessions on Linux when telemetry indicates two users are present, suggesting anomalous or suspicious session activity.
Florian Roth (Nextron Systems), Huntrule TeamLinuxguacamoleHigh306Free2020-07-03Windows Registry Printer Driver Installations with Empty Manufacturer Field
Alerts on Windows registry printer driver environment updates where Manufacturer is set to empty.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh309Free2020-07-01Windows Registry Event Triggered by RedMimicry Winnti Playbook (HTMLHelp\data)
Alerts on Windows registry events targeting HKLM\SOFTWARE\Microsoft\HTMLHelp\data associated with the RedMimicry Winnti playbook.
Alexander Rausch, Huntrule TeamWindowsregistry_eventHigh122Free2020-06-24Windows process execution matching Winnti RedMimicry playbook (rundll32/cmd with temp batch and gthread/sigcmm DLLs)
Flags rundll32.exe/cmd.exe launches with Winnti-specific DLL and temp batch indicators.
Alexander Rausch, Huntrule TeamWindowsprocess_creationHigh40Free2020-06-24Windows File Drops Matching Winnti Dropper Artifacts (gthread/sigcmm DLLs, tmp.bat)
Detects Windows file drops of specific DLLs and a Windows Temp batch filename pattern associated with a Winnti dropper scenario.
Alexander Rausch, Huntrule TeamWindowsfile_eventHigh139Free2020-06-24Windows Process Creation: Detect reg.exe Add Control Panel CPL Items
Alerts on reg.exe adding Control Panel CPL items via CurrentVersion\Control Panel\CPLs, a common vector for stealthy execution/persistence.
Kyaw Min Thein, Furkan Caliskan (@caliskanfurkan_), Huntrule TeamWindowsprocess_creationHigh71Free2020-06-22Windows Process Creation: IE Security Registry Values Disabled via Command Line
Alerts on Windows command lines that set IE hardening-related registry values to disable security features.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3610Free2020-06-19Windows Registry Modification via Process Creation Command Lines Indicative of Ke3chang/TidePool
Alerts on Windows process command lines that set IE hardening and related Internet Explorer registry properties consistent with Ke3chang/TidePool.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh63Free2020-06-18Windows Process Creation: Possible Path Traversal in cmd.exe Command Line
Alerts on Windows cmd.exe executions with "../.." path traversal indicators in parent/child command lines.
xknow @xknow_infosec, Tim Shelton, Huntrule TeamWindowsprocess_creationHigh425Free2020-06-11Windows file indicators for Octopus Scanner malware artifacts
Alerts on Windows file activity for Octopus Scanner-related filenames (Cache134.dat, ExplorerSync.db) in AppData.
NVISO, Huntrule TeamWindowsfile_eventHigh181Free2020-06-09Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Alerts on Windows consent-store registry entries showing webcam/microphone access tied to Temp or public user paths.
Den Iuzvyk, Huntrule TeamWindowsregistry_eventHigh112Free2020-06-07Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags
Alerts on Sysmon registry sets that set .NET ETWEnabled/COMPlus ETW flags to 0, impairing ETW-based telemetry.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh213Free2020-06-05Windows Registry ETW Logging Disabled for .NET via Security Event 4657
Alerts when .NET ETW logging is disabled via registry changes (ETWEnabled or COMPlus ETW settings) using Event ID 4657.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh172Free2020-06-05Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Identifies Windows PowerShell command lines commonly used by Covenant launchers, including hidden/encoded execution patterns.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2020-06-04