Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry Set: ServiceDll Path Ending with \CurrentControlSet\Services\wercplsupport\Parameters\ServiceDll
Alerts on Windows registry writes to a specific Services\wercplsupport\Parameters\ServiceDll target path.
Trent Liffick (@tliffick), Huntrule TeamWindowsregistry_setHigh72Free2020-05-14Windows Persistence Attempt via sc config or wmic COR_PROFILER (Blue Mockingbird)
Flags sc.exe sc config and wmic.exe COR_PROFILER command lines tied to wercplsupporte.dll references.
Trent Liffick (@tliffick), Huntrule TeamWindowsprocess_creationHigh111Free2020-05-14Windows Registry Ports Key Changes with Script/Binary File Indicators
Flags registry modifications to the Ports key with path- or executable/script-like details that may indicate printer-based exploitation attempts.
EagleEye Team, Florian Roth (Nextron Systems), NVISO, Huntrule TeamWindowsregistry_setHigh82Free2020-05-13Windows Process Creation: Add-PrinterPort Commands with Suspicious File Paths
Flags suspicious Add-PrinterPort usage referencing .exe/.dll/.bat or “Generic / Text Only” in Windows process command lines.
EagleEye Team, Florian Roth, Huntrule TeamWindowsprocess_creationHigh107Free2020-05-13Windows: Detect rar.exe Archive Creation Using Password or Compression Options
Alerts on rar.exe command lines that include both password protection (-hp) and additional compression/archive flags.
"@ROxPinTeddy, Huntrule Team"Windowsprocess_creationHigh308Free2020-05-12Windows: Advanced IP Scanner (PUA) Execution via Process Creation
Identifies Windows processes running Advanced IP Scanner using filename/description and command-line arguments.
Nasreddine Bencherchali (Nextron Systems), @ROxPinTeddy, Huntrule TeamWindowsprocess_creationMedium366Free2020-05-12Advanced IP Scanner Execution from Temp Folder via Windows File Events
Flags file activity targeting Advanced IP Scanner 2 under a Windows user Temp directory.
"@ROxPinTeddy, Huntrule Team"Windowsfile_eventMedium193Free2020-05-12Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
NVISO, Huntrule TeamWindowsfile_eventHigh82Free2020-05-11Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical169Free2020-05-08Azure Activity Logs: Alert on First-Time Source IP for Subscription-Level Rare Operations
Alerts when specified Azure subscription operations occur from a new, previously unseen source IP.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium142Free2020-05-07Azure Activity Logs: Granting Role Assignments from New Source IPs
Alerts on Azure role assignment permission grants when they originate from a new source IP in Activity Logs.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium359Free2020-05-07Azure Activity Logs: High Rate of VM Creations or Deployment Writes
Flags Azure activity log events showing VM creation or deployment write operations occurring at an anomalously high volume.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium153Free2020-05-07Windows Security Log: Metasploit SMB NTLM Logon (4624/4625, 4776)
Detects Metasploit-linked NTLM SMB authentication activity using Windows 4624/4625 and 4776 with 16-char workstation names.
Chakib Gzenayi (@Chak092), Hosni Mribah, Huntrule TeamWindowssecurityHigh3710Free2020-05-06Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Alerts on Windows failed logons (4625) originating from IPs outside private/local ranges.
NVISO, Huntrule TeamWindowssecurityMedium356Free2020-05-06Windows Fax Service ualapi.dll Side-Loading via fxssvc.exe
Flags fxssvc.exe loading ualapi.dll from unexpected paths, indicating potential DLL side-loading for privilege escalation.
NVISO, Huntrule TeamWindowsimage_loadHigh72Free2020-05-04