Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Boot Configuration Tampering via bcdedit.exe
Flags bcdedit.exe commands that set boot status policy to ignore failures and disable recovery (recoveryenabled=no).
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2019-10-24Windows at.exe Interactive Job via Process Creation
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh163Free2019-10-24Windows PowerShell ScriptBlock Web Request Cmdlets and Command-Line Tools
Alerts when PowerShell script blocks reference web request and download cmdlets/commands, excluding a specific guest configuration path.
James Pemberton / @4A616D6573, Huntrule TeamWindowsps_scriptMedium122Free2019-10-24Windows: Uncommon Outbound Kerberos Traffic on Port 88
Alerts on initiated outbound connections to Kerberos TCP/88 from unexpected Windows processes.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowsnetwork_connectionMedium199Free2019-10-24Windows PowerShell Profile File Creation or Modification
Alerts on creation or modification of PowerShell profile.ps1 files in typical Windows and PowerShell 7 locations.
HieuTT35, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium143Free2019-10-24Windows Service Control Manager TAP Driver Installation (tap0901)
Flags Windows service installation events for TAP driver image paths containing 'tap0901'.
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowssystemMedium82Free2019-10-24Windows Security 4673: Failed LsaRegisterLogonProcess Handle Registration
Alerts on failed attempts to call LsaRegisterLogonProcess() in Windows Security (Event 4673), tied to the SeTcbPrivilege requirement.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh154Free2019-10-24Windows Security 4697: TAP Driver Service Installation (tap0901)
Alerts on Windows Security EID 4697 service installation events for TAP driver files containing "tap0901."
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowssecurityLow133Free2019-10-24Uncommon Outbound Kerberos Port 88 Network Connections (Windows Security Event 5156)
Alerts on rare outbound Kerberos (port 88) connections from non-browser/non-lsass processes using Windows Event 5156.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowssecurityMedium3110Free2019-10-24Windows Security 4611: Rubeus-Indicative New Trusted Logon Process Registration
Alerts on Windows Security Event 4611 registering a new trusted logon process named 'User32LogonProcesss'.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh131Free2019-10-24Linux: Detect Modification of /etc/ld.so.preload for Shared Object Injection
Flags auditd activity where /etc/ld.so.preload is modified, indicating potential shared object injection.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamLinuxauditdHigh92Free2019-10-24Windows Process Execution of Common Tunneling Tools (httptunnel, plink, socat, stunnel)
Alerts on Windows execution of htptunnel.exe, plink.exe, socat.exe, or stunnel.exe that may be used for tunneling.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationMedium60Free2019-10-24Windows Registry COM Hijacking via TreatAs Subkey in CLSID
Alerts on registry modifications to HKU\Classes\CLSID\*\TreatAs that may indicate COM object hijacking/persistence.
Kutepov Anton, oscd.community, Huntrule TeamWindowsregistry_setMedium215Free2019-10-23Windows: Sysmon filter driver unloaded using fltMC.exe
Identifies fltMC.exe commands attempting to unload the Sysmon filter driver via “unload sysmon”.
Kirill Kiryanov, oscd.community, Huntrule TeamWindowsprocess_creationHigh397Free2019-10-23Linux auditd: dd overwrites a file using /dev/null or /dev/zero
Flags dd command lines that overwrite files by sourcing data from /dev/null or /dev/zero.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdLow92Free2019-10-23