Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Security: AD object replication attempted by non-machine account (Event ID 4662)
Alerts on AD replication-related object access events where the requester is not a machine account.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical103Free2019-07-26Windows regsvr32 Executes DLL with Uncommon Extension in Command Line
Alerts when regsvr32.exe is launched with a DLL extension pattern that is not in the common list.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium285Free2019-07-17Windows regsvr32 Usage of /i Without /n Flag
Alerts on regsvr32.exe invocations using /i: without the usually paired /n flag.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium166Free2019-07-13Windows: Explorer factory invocation causing process tree break
Alerts on process creation command lines showing explorer.exe factory and /root usage consistent with an explorer-based process tree break.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @gott_cyber, Huntrule TeamWindowsprocess_creationMedium84Free2019-06-29Windows Process Creation: Executable Extension Masquerading with .exe After Decoy Extension
Alerts on Windows processes whose paths/command lines use misleading double extensions ending in .exe to cloak executable execution.
Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2019-06-26Windows Security Log LSASS Access by Non-Computer Account Process
Alerts on suspicious LSASS access attempts (4663/4656) targeting lsass.exe by non-system processes using flagged access masks.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium3610Free2019-06-20Windows Security Event 4662 Detects DPAPI Domain Backup Key Extraction from Domain Controllers
Detects read access to LSA secret DPAPI domain backup key objects in Windows Event ID 4662.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh123Free2019-06-20Windows: Suspicious userinit.exe Child Process Creation
Alerts when userinit.exe spawns an atypical child process, excluding known benign explorer and netlogon command-line patterns.
Florian Roth (Nextron Systems), Samir Bousseaden (idea), Huntrule TeamWindowsprocess_creationMedium61Free2019-06-17Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh286Free2019-06-15Windows Process Creation: Suspicious Renamed Binary Masquerading as Common Tools
Flags Windows executions where Sysmon OriginalFileName matches common tools but the process Image name ends differently.
Matthew Green @mgreen27, Ecco, James Pemberton @4A616D6573, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationMedium149Free2019-06-15Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Flags Windows 4624 successful logons consistent with Pass-the-Hash activity using NtLmSsp or seclogo.
Dave Kennedy, Jeff Warren (method) / David Vassallo (rule), Huntrule TeamWindowssecurityMedium30Free2019-06-14Webserver URL Enumeration for Exposed .git Paths via GET Keyword
Alerts when web requests include .git/ in the URL, suggesting source code enumeration against version control paths.
James Ahearn, Huntrule TeamWebwebserverMedium102Free2019-06-08Windows Process Creation: Renamed jusched.exe Execution via Java Scheduler Names
Alerts when Java Update Scheduler descriptions are used to execute a process ending with \jusched.exe on Windows.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh238Free2019-06-04Windows Security 4625 Logon Failures to TargetUserName AAAAAAA Indicative of RDP Scan PoC
Alerts on Windows failed logon (4625) events matching a BlueKeep scanner PoC TargetUserName value.
Florian Roth (Nextron Systems), Adam Bradbury (idea), Huntrule TeamWindowssecurityHigh152Free2019-06-02Windows System Log RDP TermDD Errors Matching EventIDs 50 or 56
Flags suspicious TermDD RDP error events (Event IDs 50/56) on Windows that may indicate CVE-2019-0708 activity.
Lionel PRAT, Christophe BROCAS, @atc_project (improvements), Huntrule TeamWindowssystemMedium81Free2019-05-24