Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
WebDAV Delivery of Executable Files over HTTP (Zeek)
Flags Zeek HTTP events where WebDAV traffic serves an .exe with MIME type 'dosexec'.
SOC Prime, Adam Swan, Huntrule TeamZeekhttpMedium72Free2020-05-01Windows winget Installs Applications Using Local Manifest File
Flags winget.exe install commands that specify a local manifest file via -m/--manifest.
Sreeman, Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium101Free2020-04-21Windows Process Command Lines Writing Malicious Files to C:\Windows\Fonts
Flags Windows command lines that create or copy files into C:\Windows\Fonts\ using suspicious file extensions.
Sreeman, Huntrule TeamWindowsprocess_creationMedium356Free2020-04-21Windows Netsh.exe WLAN profile key clearing used for WiFi credential harvesting
Detects netsh.exe command-line activity targeting WLAN and clearing keys, indicative of potential WiFi credential harvesting on Windows.
Andreas Hunkeler (@Karneades), oscd.community, Huntrule TeamWindowsprocess_creationMedium92Free2020-04-20Windows: Process Execution of Suspicious hxtsr.exe (Outside WindowsApps)
Alerts when hxtsr.exe runs from a non-expected WindowsApps Microsoft.WindowsCommunicationsApps location.
Sreeman, Huntrule TeamWindowsprocess_creationMedium246Free2020-04-17AWS CloudTrail EC2 CreateInstanceExportTask Failure
Flags failed EC2 VM export task creation events in AWS CloudTrail to surface potential instance data extraction attempts.
Diogo Braz, Huntrule TeamAwscloudtrailLow101Free2020-04-16Proxy Downloads Containing /pwndrop/ (PwnDrp Web Server)
Alerts on proxy requests to URIs containing '/pwndrop/', consistent with PwnDrp-style web delivery.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical122Free2020-04-15PowerShell Local User Creation via New-LocalUser
Flags PowerShell usage of New-LocalUser, indicating creation of a Windows local user.
"@ROxPinTeddy, Huntrule Team"Windowsps_scriptMedium40Free2020-04-11Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Flags Zeek-observed SMB share file transfers involving credential/dump-related filenames.
"@neu5ron, Teymur Kheirkhabarov, oscd.community, Huntrule Team"Zeeksmb_filesMedium178Free2020-04-02Zeek SMB File Access to Sensitive Email/Database/Backup Extensions
Alerts on Zeek-observed SMB file accesses to filenames ending with high-value sensitive extensions.
Samir Bousseaden, @neu5ron, Huntrule TeamZeeksmb_filesMedium396Free2020-04-02Windows: Alert on Suspicious HH.EXE Process Execution
Alerts on HH.exe execution where the command line references temp, downloads, Outlook, or other writable directories.
Maxim Pavlunin, Huntrule TeamWindowsprocess_creationHigh71Free2020-04-01Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2020-04-01Windows Security Event 4662: Non-Machine Account Reads Domain User Object Properties
Alert on AD user property read attempts in Windows Event 4662 from non-machine accounts.
Maxime Thiebaut (@0xThiebaut), Huntrule TeamWindowssecurityMedium93Free2020-03-30Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
NVISO, Huntrule TeamWindowsps_scriptHigh132Free2020-03-26Windows Process Creation: Java exploitation chain targeting Zoho ManageEngine Desktop Central (CVE-2020-10189)
Alerts on cmd/Pwsh/BITSAdmin and other command utilities launched by the Desktop Central Java runtime.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2020-03-25