Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Writes (Security 5136/5145)
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh126Free2019-04-03Windows Security 4661 Detects Privileged AD User/Group SID Enumeration via SAM
Identifies SAM_USER/SAM_GROUP access events (4661) aimed at privileged SIDs or names containing 'admin' while ignoring computer accounts.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh357Free2019-04-03Windows Security 5136: Modify AD ACL for DCSync Extended Right via ntSecurityDescriptor
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, Huntrule TeamWindowssecurityHigh274Free2019-04-03Windows Suspicious EXE in User Directory Launched by Microsoft Office Applications
Alert on Office spawning a .exe from C:\users\ (except when the child is Teams.exe).
Jason Lynch, Huntrule TeamWindowsprocess_creationHigh61Free2019-04-02Linux Suspicious Reverse Shell Command-Line Execution Patterns
Alerts on Linux command lines containing reverse-shell-style strings such as /dev/tcp redirections, netcat pipes, and socket connect patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High112Free2019-04-02Windows process creation matching EmpireMonkey-style jscript execution from Temp Errors.bat
Alerts on Windows executions that combine /e:jscript with a \Local\Temp\Errors.bat batch path.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh405Free2019-04-02Windows Security Logon Event ID 4800: Workstation Lock After Inactivity
Locked Workstation
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityInformational337Free2019-03-26Firewall Rule Accepting Cleartext Protocol Ports
Alerts on firewall-allowed traffic to common service ports that may carry credentials over unencrypted channels.
Alexandr Yampolskyi, SOC Prime, Tim Shelton, Huntrule TeamNetworkfirewallLow62Free2019-03-26Qualys Vulnerability Scans Indicating Default Credentials Use
Flags Qualys vulnerability scan results that indicate potential default credential usage on scanned hosts.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamQualys—Medium20Free2019-03-26Cleartext Authentication via Netflow to Common Service Ports
Alerts on Netflow flows to specific service ports that may indicate cleartext protocol use and potential credential exposure.
Alexandr Yampolskyi, SOC Prime, Huntrule Team—netflowLow40Free2019-03-26Windows ADSI Schema Cache (.sch) File Creation by Uncommon Process
Alerts on .sch cache file creation in the Windows SchCache directory by uncommon executables.
xknow @xknow_infosec, Tim Shelton, Huntrule TeamWindowsfile_eventMedium189Free2019-03-24Windows Security Event 5136: Suspicious LDAP attribute display names used
Alerts on Event 5136 containing specific LDAP display names indicative of LDAP-based data exchange.
xknow @xknow_infosec, Huntrule TeamWindowssecurityHigh115Free2019-03-24Windows ETW Trace Evasion via Clearing/Disabling Logs or Providers
Identifies command-line attempts to clear/disable ETW traces or remove/modify ETW providers on Windows.
"@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule Team"Windowsprocess_creationHigh112Free2019-03-22Qualys: Alert When Firewall Product Is Not Detected on a Host
Alerts when Qualys reports a host missing a detectable firewall product during vulnerability management scanning.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamQualys—Low50Free2019-03-19Microsoft BITS Proxy Activity to Uncommon Top-Level Domains
Flags Microsoft BITS-initiated proxy requests to domains using uncommon TLDs.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWebproxyHigh209Free2019-03-07