Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,286 rules
Linux auditd alerts on syslog daemon configuration file changes
Alerts when syslog daemon configuration files are changed on a Linux host via auditd PATH events.
Mikhail Larin, oscd.community, Huntrule TeamLinuxauditdHigh132Free2019-10-25Linux auditd: Monitor changes to /etc/audit, /etc/libaudit.conf, and /etc/audisp files
Flags modifications to Linux auditd configuration files that can weaken host auditing.
Mikhail Larin, oscd.community, Huntrule TeamLinuxauditdHigh111Free2019-10-25Windows Process Creation: WSReset.exe Used with Non-CONHOST Child Process
Alerts when wsreset.exe spawns a process other than conhost.exe, a potential UAC-bypass precursor.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Florian Roth, Huntrule TeamWindowsprocess_creationHigh315Free2019-10-24Windows: Detect Fodhelper.exe spawned processes indicative of UAC bypass
Flags process creation where the parent is Fodhelper.exe, a common UAC bypass execution pattern on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2019-10-24Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Alerts when cmstp.exe is launched with INF installation and silent/auto options indicating a UAC-bypass style behavior.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh192Free2019-10-24Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2019-10-24Windows Mshta.exe Launching JavaScript via Command Line
Detects Mshta.exe executions where the command line includes "javascript".
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh326Free2019-10-24Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Alerts when Hwp.exe launches gbb.exe, a suspicious child process pattern on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2019-10-24Windows Execution of dnscat2 and iodine DNS Exfiltration/Tunneling Tools
Flags Windows execution of DNS tunneling/exfiltration tools identified by iodine.exe or dnscat2 in process creation events.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh203Free2019-10-24Windows Boot Configuration Tampering via bcdedit.exe
Flags bcdedit.exe commands that set boot status policy to ignore failures and disable recovery (recoveryenabled=no).
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2019-10-24Windows at.exe Interactive Job via Process Creation
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh173Free2019-10-24Windows Security 4673: Failed LsaRegisterLogonProcess Handle Registration
Alerts on failed attempts to call LsaRegisterLogonProcess() in Windows Security (Event 4673), tied to the SeTcbPrivilege requirement.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh154Free2019-10-24Windows Security 4611: Rubeus-Indicative New Trusted Logon Process Registration
Alerts on Windows Security Event 4611 registering a new trusted logon process named 'User32LogonProcesss'.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh141Free2019-10-24Linux: Detect Modification of /etc/ld.so.preload for Shared Object Injection
Flags auditd activity where /etc/ld.so.preload is modified, indicating potential shared object injection.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamLinuxauditdHigh92Free2019-10-24Windows: Sysmon filter driver unloaded using fltMC.exe
Identifies fltMC.exe commands attempting to unload the Sysmon filter driver via “unload sysmon”.
Kirill Kiryanov, oscd.community, Huntrule TeamWindowsprocess_creationHigh407Free2019-10-23