Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Cisco IOS AAA Crypto PKI Export/Import Commands
Alerts on Cisco IOS AAA logs showing crypto PKI export of private keys or PKI import of certificates/trustpoints.
Austin Clark, Huntrule TeamCiscoaaaHigh305Free2019-08-12Cisco Network OS Log and Archive Clearing via “clear logging” Commands
Flags Cisco network OS attempts to clear logs or archives via AAA command text.
Austin Clark, Huntrule TeamCiscoaaaHigh234Free2019-08-12Cisco AAA configuration changes enabling SPAN/RSPAN monitoring capture
Alerts on Cisco AAA logs referencing SPAN/RSPAN or monitor capture point configuration changes.
Austin Clark, Huntrule TeamCiscoaaaMedium72Free2019-08-11Cisco AAA: Detection of 'show history' and 'show logging' command input
Alerts on Cisco AAA command input attempting to view history or logging via 'show history'/'show logging' commands.
Austin Clark, Huntrule TeamCiscoaaaMedium141Free2019-08-11Cisco IOS AAA Logging Disabled via 'no logging' and 'no aaa new-model' commands
Flags Cisco AAA command text that includes 'no logging' and/or 'no aaa new-model' to indicate logging being turned off.
Austin Clark, Huntrule TeamCiscoaaaHigh93Free2019-08-11Cisco AAA Command Output Collection: show running/startup-config and archive config
Detects Cisco command strings attempting to collect device configuration via show running/startup/archived config.
Austin Clark, Huntrule TeamCiscoaaaLow4010Free2019-08-11Uncommon PowerShell HostApplication Values in Windows PowerShell Start Logs
Detects PowerShell classic start events with unusual HostApplication values that may indicate evasion of powershell.exe-focused detections.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsps_classic_startMedium30Free2019-08-11Windows CreateRemoteThread with LoadLibraryA likely DLL injection
Alerts on CreateRemoteThread starting LoadLibraryA from kernel32.dll, consistent with DLL injection attempts.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowscreate_remote_threadMedium30Free2019-08-11Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowsps_moduleHigh103Free2019-08-10Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Flags Windows telemetry indicating a remote PowerShell session startup using wsmprovhost.exe with a specified host parameter.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsps_classic_startLow62Free2019-08-10Windows Security: Network Access to protected_storage (IPC)
Flags Windows network share access to protected_storage through IPC from Security event 5145.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh63Free2019-08-10Windows Security Event 4692 Detecting DPAPI Domain Master Key Backup Attempt
Flags Windows Event ID 4692 indicating an attempt to back up the DPAPI domain master key.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium214Free2019-08-10Windows Image Load: WMI DLLs Loaded by Uncommon Process
Alert on loading of common WMI DLLs by processes outside typical system/.NET paths.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsimage_loadLow50Free2019-08-10Windows: MMC spawning command-line executables
Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.
Karneades, Swisscom CSIRT, Huntrule TeamWindowsprocess_creationHigh101Free2019-08-05Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.
Nik Seetharaman, Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh332Free2019-07-31