Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,279 rules
Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-04-15Firewall Alerts for C2 IP Traffic to 69.42.98.86 and 89.185.234.145
Alerts when firewall traffic involves the two specified IPs associated with presumed C2 communication.
Florian Roth (Nextron Systems), Huntrule Team—firewallHigh376Free2017-04-15Windows Security: AD user/computer backdoor via msDS-AllowedToDelegateTo and delegation attributes
Alerts on AD delegation-related attribute changes that may create credentialless account control paths.
"@neu5ron, Huntrule Team"WindowssecurityHigh198Free2017-04-13PowerShell Credential Prompt via PromptForCredential
Flags PowerShell scripts that reference "PromptForCredential", indicating credential prompt behavior in Script Block Logging.
John Lambert (idea), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh389Free2017-04-09Linux Command-Line Indicators of Equation Group Tooling
Flags execution of known suspicious Linux shell command patterns tied to Equation Group-style scripting and tooling.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High152Free2017-04-09Windows CScript and csvde Command-Line Execution Patterns Suggesting Cloud Hopper Activity
Detects cscript VBScript shell execution and csvde writing log files into C:\windows\web\.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2017-04-07Windows Service Install (Event ID 7045) for srservice, ipvpn, hkmsvc
Alerts on Windows service creation events (7045) for srservice, ipvpn, and hkmsvc service names.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh111Free2017-03-31Windows Registry UAC Bypass via Event Viewer Command Key (mscfile shell open command)
Alerts on registry changes to the mscfile shell open command key consistent with an Event Viewer UAC bypass technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh131Free2017-03-19Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-03-19Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh83Free2017-03-19Windows network connection from process running in suspicious or uncommon file paths
Alerts on Windows network connections initiated by processes executing from suspicious or uncommon directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh209Free2017-03-19Windows UAC Bypass Indicator via sdclt Registry Key Manipulation
Alerts on registry set activity consistent with sdclt-related UAC bypass key manipulation.
Omer Yampel, Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh92Free2017-03-17Linux Log Shellshock Expression Pattern Matching
Identifies Shellshock-style function-body expressions in Linux log data via keyword string matches.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High309Free2017-03-14Windows PowerShell ScriptBlock with Encoded, Hidden, or Noninteractive Execution Parameters
Alerts on PowerShell ScriptBlockText containing encoded command, hidden window, or noninteractive execution parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2017-03-12Suspicious PowerShell Module Execution Using Encoded, Hidden, or Noninteractive Context (Windows)
Alerts on PowerShell module executions using encoded commands, hidden windows, or noninteractive flags to evade visibility and interaction.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh167Free2017-03-12