Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,420 rules
Windows process access targeting verclsid.exe with Office/VBA shellcode traces
Flags broad access to verclsid.exe from Microsoft Office/VBA contexts with VBE7.DLL call traces consistent with shellcode injection.
John Lambert (tech), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh106Free2017-03-04Linux Syslog Buffer Overflow Exploit Attempt Keywords
Alerts on Linux syslog entries containing known buffer overflow/stack-smashing attempt keyword patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High2410Free2017-03-01Linux ClamAV alerts for Trojan, Webshell, Rootkit, Htran, VirTool detections
Detects ClamAV log entries with keyword-based indicators for Trojans, webshells, rootkits, and Htran.
Florian Roth (Nextron Systems), Huntrule TeamLinuxclamavHigh152Free2017-03-01Apache worker crash logs with "Segmentation Fault" exit signal
Alerts on Apache error log lines showing a worker process crashed with an exit signal Segmentation Fault.
Florian Roth (Nextron Systems), Huntrule TeamWebapacheHigh325Free2017-02-28Windows LSASS Remote Thread Creation Indicative of Password Dumping
Flags Windows remote thread creation targeting lsass.exe, a common pattern in password dumping activity.
Thomas Patzke, Huntrule TeamWindowscreate_remote_threadHigh437Free2017-02-19Windows Security Event 4794 Password Change for DSRM Account
Flags potential changes to the DSRM administrator password on Windows domain controllers using Security EventID 4794.
Thomas Patzke, Huntrule TeamWindowssecurityHigh102Free2017-02-19Windows Application Logs: Match Antivirus Signature and Malware Keyword Hits
Alerts on Windows application log lines containing known AV signatures and malware keywords, excluding some anti-ransomware/keygen/crack terms.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule TeamWindowsapplicationHigh73Free2017-02-19Windows Webshell Command Strings in Webserver GET Requests
Identifies GET requests with URL-encoded Windows command strings consistent with webshell behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh151Free2017-02-19Windows Driver Load from Temporary Directory Paths
Detects Windows driver loads whose ImageLoaded path contains the temporary directory (\Temp\).
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh3710Free2017-02-12Windows Security: Detect LSASS handle access for SAM_DOMAIN (0x705)
Flags handle opens to lsass.exe with access mask 0x705 targeting SAM_DOMAIN, indicative of credential dumping.
sigma, Huntrule TeamWindowssecurityHigh102Free2017-02-12Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Alerts on Windows Security failures for Kerberos TGT-related operations using specific Kerberos event IDs and status codes.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh271Free2017-02-10Windows Event Logs: Mimikatz Keyword Indicators
Detects Mimikatz-related keywords in Windows event logs while filtering Sysmon EventID 15 to limit noise.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindows—High427Free2017-01-10Windows Security and Eventlog Cleared via Event IDs 517 or 1102
Flags Windows event log clearing using Security Event ID 517 and Microsoft-Windows-Eventlog Event ID 1102.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh388Free2017-01-10Windows Webshell Recon Command-Line Keywords via Web Server Processes
Flags Windows process chains where web server parents spawn reconnaissance- and execution-related command lines indicative of webshell activity.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson, Huntrule TeamWindowsprocess_creationHigh317Free2017-01-01Windows WerFault Access to lsass.exe Indicative of Credential Dumping Attempts
Alert on WerFault.exe gaining broad access to lsass.exe, consistent with credential dumping attempts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh273Free2012-06-27