Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,283 rules
Windows GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Writes (Security 5136/5145)
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh156Free2019-04-03Windows Security 4661 Detects Privileged AD User/Group SID Enumeration via SAM
Identifies SAM_USER/SAM_GROUP access events (4661) aimed at privileged SIDs or names containing 'admin' while ignoring computer accounts.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh367Free2019-04-03Windows Security 5136: Modify AD ACL for DCSync Extended Right via ntSecurityDescriptor
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, Huntrule TeamWindowssecurityHigh294Free2019-04-03Windows Suspicious EXE in User Directory Launched by Microsoft Office Applications
Alert on Office spawning a .exe from C:\users\ (except when the child is Teams.exe).
Jason Lynch, Huntrule TeamWindowsprocess_creationHigh71Free2019-04-02Linux Suspicious Reverse Shell Command-Line Execution Patterns
Alerts on Linux command lines containing reverse-shell-style strings such as /dev/tcp redirections, netcat pipes, and socket connect patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High112Free2019-04-02Windows process creation matching EmpireMonkey-style jscript execution from Temp Errors.bat
Alerts on Windows executions that combine /e:jscript with a \Local\Temp\Errors.bat batch path.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh435Free2019-04-02Windows Security Event 5136: Suspicious LDAP attribute display names used
Alerts on Event 5136 containing specific LDAP display names indicative of LDAP-based data exchange.
xknow @xknow_infosec, Huntrule TeamWindowssecurityHigh125Free2019-03-24Windows ETW Trace Evasion via Clearing/Disabling Logs or Providers
Identifies command-line attempts to clear/disable ETW traces or remove/modify ETW providers on Windows.
"@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule Team"Windowsprocess_creationHigh152Free2019-03-22Microsoft BITS Proxy Activity to Uncommon Top-Level Domains
Flags Microsoft BITS-initiated proxy requests to domains using uncommon TLDs.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWebproxyHigh209Free2019-03-07Windows: PowerShell-triggered HTA retrieval and execution with registry and process disruption
Alerts on Windows process creation where PowerShell uses mshta over HTTP and includes .hta, registry query, and cmd.exe termination.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh411Free2019-02-24Windows mshta.exe Execution Using Non-HTA File Extensions
Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.
Diego Perez (@darkquassar), Markus Neis, Swisscom (Improve Rule), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2019-02-22Windows: RDP Session Startup Folder Backdoor via tsclient Share Targeting Startup Path
Flags mstsc.exe activity writing to the Windows Startup folder, indicating potential RDP session backdoor placement.
Samir Bousseaden, Huntrule TeamWindowsfile_eventHigh153Free2019-02-21Windows svchost RDP via Reverse SSH Loopback Tunnel to 127.0.0.0/8:3389
Flags svchost.exe opening RDP (TCP 3389) connections to loopback, consistent with tunneled reverse access behavior.
Samir Bousseaden, Huntrule TeamWindowsnetwork_connectionHigh2410Free2019-02-16Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh143Free2019-02-16Windows Registry Persistence Attempt Using AppDataLow Ursnif-Related Path
Alerts on Windows registry key additions matching a Ursnif-associated TargetObject path.
megan201296, Huntrule TeamWindowsregistry_addHigh162Free2019-02-13