Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows PowerShell Remote Thread Creation Into Uncommon Target Processes
Alerts on PowerShell creating remote threads in rundll32.exe or regsvr32.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_remote_threadMedium165Free2018-06-25Windows Sysprep Execution Targeting AppData Directory
Alerts when sysprep.exe runs with an AppData directory present in the command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium73Free2018-06-22Windows NTLM authentication events (Event ID 8002)
Alerts on Windows NTLM authentication occurrences based on Event ID 8002 from Microsoft-Windows-NTLM/Operational.
Florian Roth (Nextron Systems), Huntrule TeamWindowsntlmLow1810Free2018-06-08Windows Process Creation: svchost.exe Spawns mshta.exe (LethalHTA)
Alerts on Windows instances where svchost.exe spawns mshta.exe, indicating potential LethalHTA execution.
Markus Neis, Huntrule TeamWindowsprocess_creationHigh83Free2018-06-07Suspicious Telegram API proxy access without Telegram User-Agent
Alerts on api.telegram.org requests where the User-Agent lacks common Telegram bot identifiers.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium72Free2018-06-05Suspicious DNS queries to api.telegram.org for Telegram Bot API traffic
Flags DNS queries to api.telegram.org that may indicate Telegram Bot API usage by bots or malware.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsMedium97Free2018-06-05Windows NTFS Alternate Data Stream Creation with Non-Default Imphash
Alerts on NTFS ADS creation where the stream hash includes a non-null IMPHASH marker, consistent with hidden executables.
Florian Roth (Nextron Systems), @0xrawsec, Huntrule TeamWindowscreate_stream_hashMedium101Free2018-06-03Suspicious DNS Queries Containing Base64-Padding Pattern (==.)
Alerts on DNS queries containing the base64 delimiter pattern '==.' consistent with encoded data in DNS.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsMedium142Free2018-05-10Cobalt Strike-style DNS Beaconing Queries (DNS)
Flags DNS queries with Cobalt Strike-style stage subdomain patterns used for covert beaconing.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsCritical81Free2018-05-10Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit
Flags registry changes to IFEO GlobalFlag and SilentProcessExit keys that can enable stealthy persistence or process redirection.
Karneades, Jonhnathan Ribeiro, Florian Roth, Huntrule TeamWindowsregistry_setHigh74Free2018-04-11Windows Process Creation: Access to Domain Group Policy in SYSVOL
Flags Windows processes that reference SYSVOL \policies paths in their command line.
Markus Neis, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium113Free2018-04-09Windows File Events: Known Offensive PowerShell Script File Creation
Alerts on creation of known offensive PowerShell/PowerShell module filenames on Windows.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Mustafa Kaan Demir, Georg Lauenstein, Huntrule TeamWindowsfile_eventHigh242Free2018-04-07Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh208Free2018-04-06Windows: Suspicious Process Spawning from Microsoft Office Applications
Alerts when Office apps spawn common execution tools or scripts from typical attacker staging paths on Windows.
Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io, Huntrule TeamWindowsprocess_creationHigh122Free2018-04-06Windows Proxy Activity Using Microsoft-WebDAV-MiniRedir GET User-Agent
Alerts on proxy HTTP GET requests using the Microsoft-WebDAV-MiniRedir/ User-Agent prefix associated with file download behavior.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh50Free2018-04-06