Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,286 rules
Windows Formbook-style process execution deleting dropped payloads from AppData Temp via cmd
Flags Windows process creation where an .exe runs deletion commands to remove dropper artifacts from AppData Temp/Desktop.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh143Free2019-09-30Windows Process Creation: Emotet-like Command-Line Patterns
Alerts on Windows process executions with command-line indicators consistent with Emotet-like staging and encoded payload usage.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2019-09-30Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2019-09-26Windows fsutil.exe Suspicious USN Journal and File Zeroing Parameters
Alerts when fsutil.exe is run with USN journal deletion/creation or setZeroData-style file zeroing commands.
Ecco, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationHigh117Free2019-09-26Windows Registry: Enable WDigest UseLogonCredential (Use clear-text logon credential setting)
Flags registry writes that enable WDigest UseLogonCredential, turning on potential clear-text credential storage.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh203Free2019-09-12Windows: WinRM inbound network connections to ports 5985/5986 for PowerShell remoting
Alerts on WinRM inbound connections (ports 5985/5986) consistent with remote PowerShell remoting activity.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh383Free2019-09-12Windows Suspicious Debugger Registration via Image File Execution Options
Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh92Free2019-09-06Windows Registry: Modification of WDigest IsCredGuardEnabled to Disable Credential Guard
Alerts on Windows registry changes to WDigest\IsCredGuardEnabled that may disable Credential Guard.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh245Free2019-08-25PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)
Flags PowerShell command lines containing FromBase64String along with base64-encoded UTF-16 marker patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh72Free2019-08-24Windows PowerShell Base64 Command Line Executing IEX
Identifies Windows PowerShell processes with Base64-encoded command-line content that contains an IEX execution pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2310Free2019-08-23Windows Security: SysKey-related LSA Registry Key Access (4656/4663)
Alerts on access to LSA registry keys used to compute SysKey based on Windows Security handle and registry object events.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh172Free2019-08-12Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Flags Windows handle requests to registry keys ending with \SAM using Security EventID 4656.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh122Free2019-08-12Cisco AAA local account and remote authentication changes
Flags Cisco AAA log events showing local username/account changes and remote authentication configuration updates.
Austin Clark, Huntrule TeamCiscoaaaHigh382Free2019-08-12Cisco IOS AAA Crypto PKI Export/Import Commands
Alerts on Cisco IOS AAA logs showing crypto PKI export of private keys or PKI import of certificates/trustpoints.
Austin Clark, Huntrule TeamCiscoaaaHigh305Free2019-08-12Cisco Network OS Log and Archive Clearing via “clear logging” Commands
Flags Cisco network OS attempts to clear logs or archives via AAA command text.
Austin Clark, Huntrule TeamCiscoaaaHigh234Free2019-08-12