Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process Creation: Emotet-like Command-Line Patterns
Alerts on Windows process executions with command-line indicators consistent with Emotet-like staging and encoded payload usage.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2019-09-30Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2019-09-26Windows fsutil.exe Suspicious USN Journal and File Zeroing Parameters
Alerts when fsutil.exe is run with USN journal deletion/creation or setZeroData-style file zeroing commands.
Ecco, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationHigh107Free2019-09-26Linux Service Reload/Start via systemctl or service Command Execution
Identifies Linux process executions invoking service control commands with start or reload keywords.
Jakob Weinzettl, oscd.community, CheraghiMilad, Huntrule TeamLinuxauditdLow185Free2019-09-23Linux auditd: chmod/chown process execution indicating file or folder permission changes
Flags Linux EXECVE events running chmod or chown, which commonly correspond to file/folder permission changes.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdLow264Free2019-09-23Linux auditd: Detect chattr -i removing immutable file attribute
Flags Linux processes using chattr to remove the immutable (-i) file attribute via auditd execve telemetry.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdMedium62Free2019-09-23Windows Registry: Enable WDigest UseLogonCredential (Use clear-text logon credential setting)
Flags registry writes that enable WDigest UseLogonCredential, turning on potential clear-text credential storage.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh193Free2019-09-12Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Alerts when wsmprovhost.exe is seen as a process or parent process, indicating remote PowerShell via WinRM.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium40Free2019-09-12Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents
Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.
Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements), Huntrule TeamWindowsprocess_creationLow91Free2019-09-12Windows Named Pipe Created for PowerShell PSHost Instance
Alerts on named pipe creation with a \PSHost prefix, indicating PowerShell host-related activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspipe_createdInformational30Free2019-09-12Windows Named Pipe Creation: Alternate PowerShell Host via \PSHost
Alerts on creation of \PSHost named pipes to identify alternate PowerShell host usage via Windows pipe events.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowspipe_createdMedium52Free2019-09-12Windows: WinRM inbound network connections to ports 5985/5986 for PowerShell remoting
Alerts on WinRM inbound connections (ports 5985/5986) consistent with remote PowerShell remoting activity.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh373Free2019-09-12Windows Security: Detect WRITE_DAC on AD DS objects (Event ID 4662)
Flags AD DS Security Event 4662 activity indicating WRITE_DAC permission changes on domain objects.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical101Free2019-09-12Windows Suspicious Debugger Registration via Image File Execution Options
Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh82Free2019-09-06Windows Process Creation: Empire PowerShell UAC Bypass CommandLine Pattern
Flags Windows process creation events running Empire-style PowerShell UAC bypass command fragments.
Ecco, Huntrule TeamWindowsprocess_creationCritical61Free2019-08-30