Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry: TrustRecords key modification indicating macro-based initial access
Flags Windows registry writes to Security\Trusted Documents\TrustRecords, a signal consistent with macro-enabled initial access.
Antonlovesdnb, Trent Liffick (@tliffick), Huntrule TeamWindowsregistry_eventMedium61Free2020-02-19Windows: Office Application Loads VBE VBA DLLs via Image Load Events
Flags Office apps loading VBA-related VBE DLLs, a strong indicator of VBA macro execution.
Antonlovesdnb, Huntrule TeamWindowsimage_loadHigh132Free2020-02-19Windows Office Apps Loading .NET GAC MSIL DLLs via Image Load Events
Alerts when an Office app loads a .NET DLL from the GAC_MSIL directory.
Antonlovesdnb, Huntrule TeamWindowsimage_loadHigh70Free2020-02-19Windows: CLR DLL Loaded by Office Applications
Alerts when Excel, Word, Outlook, PowerPoint, Publisher, or OneNote loads clr.dll on Windows.
Antonlovesdnb, Huntrule TeamWindowsimage_loadMedium40Free2020-02-19Windows Office Apps Loading .NET Assembly DLLs from C:\Windows\assembly
Alerts when Office applications load DLLs from C:\Windows\assembly\ via image load events.
Antonlovesdnb, Huntrule TeamWindowsimage_loadMedium40Free2020-02-19Windows Process Memory Dump via comsvcs.dll using rundll32
Alert on rundll32 loading comsvcs.dll with arguments consistent with a full process memory dump.
Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2020-02-18Windows Process Creation: Sticky Keys Backdoor via sethc.exe Replacement
Flags forced replacement of C:\Windows\System32\sethc.exe with cmd.exe consistent with a Sticky Keys backdoor.
Sreeman, Huntrule TeamWindowsprocess_creationCritical116Free2020-02-18AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance
Detects RDS restores from snapshots that result in a publicly accessible database instance in AWS CloudTrail.
faloker, Huntrule TeamAwscloudtrailHigh461Free2020-02-12AWS CloudTrail RDS ModifyDBInstance Master User Password Change
Flags AWS RDS ModifyDBInstance events that include a master user password change.
faloker, Huntrule TeamAwscloudtrailMedium132Free2020-02-12AWS CloudTrail CreateAccessKey by Another IAM User (Backdoor Key Creation)
Identifies AWS access key creation where the requester is different from the access key’s target user.
faloker, Huntrule TeamAwscloudtrailMedium2410Free2020-02-12AWS EC2 ModifyInstanceAttribute userData Startup Script Change
Detects CloudTrail EC2 userData startup script changes made via ModifyInstanceAttribute.
faloker, Huntrule TeamAwscloudtrailHigh71Free2020-02-12AWS GuardDuty CreateIPSet Trusted IP Set Changes (CloudTrail)
Alerts on CloudTrail GuardDuty CreateIPSet events that add or update trusted IP address sets.
faloker, Huntrule TeamAwscloudtrailHigh102Free2020-02-11Windows DNS analytic events for GALLIUM-related ddns QNAMEs (EventID 257)
Alert on Windows DNS analytical EventID 257 queries for GALLIUM-linked suspicious QNAMEs.
Tim Burrell, Huntrule TeamWindowsdns-server-analyticHigh306Free2020-02-07Windows Process Creation alerts on GALLIUM-associated hash IOCs
Flags Windows process executions where the file hash matches hardcoded GALLIUM-associated SHA256/SHA1 IOCs.
Tim Burrell, Huntrule TeamWindowsprocess_creationHigh1610Free2020-02-07Windows: Flag SettingSyncHost.exe used to execute RoamDiag.cmd from cmd.exe
Flags non-System32/SysWOW64 processes spawned by SettingSyncHost.exe running RoamDiag.cmd via cmd.exe /c -outputpath.
Anton Kutepov, oscd.community, Huntrule TeamWindowsprocess_creationHigh356Free2020-02-05