Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows WMI Persistence: Script Event Consumer File Writes (scrcons.exe)
Flags file writes performed by scrcons.exe, indicating potential WMI script event consumer persistence activity.
Thomas Patzke, Huntrule TeamWindowsfile_eventHigh429Free2018-03-07Windows Scheduled Task Creation via PowerShell Using schtasks.exe with ONLOGON/DAILY/ONIDLE/HOURLY
Flags PowerShell-launched schtasks.exe /Create commands matching default PowerSploit/Empire scheduled task persistence behavior.
Markus Neis, @Karneades, Huntrule TeamWindowsprocess_creationHigh241Free2018-03-06Windows rundll32 Trojan Loader Execution via Local AppData and .dat Parameters
Flags rundll32.exe launched with AppData/local .dat and .dll patterns consistent with Trojan loader behavior.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh102Free2018-03-01Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Alerts when Winword spawns a FLTLDR.exe child process, matching a CVE-2017-0261-style exploit chain.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium63Free2018-02-22WinWord spawning MicroScMgmt.exe indicative of CVE-2015-1641 exploitation on Windows
Alerts when Winword.exe starts MicroScMgmt.exe, matching a known CVE-2015-1641 exploitation behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical141Free2018-02-22Linux syslog: Detect suspicious BIND/named error messages
Alerts on Linux syslog messages with BIND named fatal or denied DNS error strings.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsyslogHigh92Free2018-02-20Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.
Roberto Rodriguez (source), Dominik Schaudel (rule), Huntrule TeamWindowssecurityHigh80Free2018-02-12Windows File Creation: QuarksPwDump Credential Dump (.dmp) in Temp\SAM-*
Flags creation of QuarksPwDump .dmp dump files in Temp with a SAM-* filename pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical313Free2018-02-10Windows msiexec Process Creation With Web URL Parameters
Alerts when msiexec is launched with command-line web URL indicators in its parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2018-02-09Windows Process Creation: svchost Running NavShExt.dll Deletion/Setting Commands
Alerts on svchost.exe process commands referencing cached NavShExt.dll deletion and execution markers consistent with Elise backdoor activity.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical386Free2018-01-31Linux Auditd: Program Executions from Suspicious Web and Data Directories
Alerts on Linux process creation when the executed binary path begins with commonly abused temp/web/data directories.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdMedium83Free2018-01-23Linux auditd: Executing suspicious chmod and cp commands
Triggers on auditd EXECVE events for chmod (777/u+s) and cp overwriting /bin/ksh or /bin/sh.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdMedium51Free2017-12-12Windows System Binary Execution From Unusual Location (Process Creation)
Alerts when common Windows system binaries run from an uncommon directory rather than standard system locations.
Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh402Free2017-11-27Web/SQL Application Logs: SQL Error Strings Indicative of Injection Probing
Flags SQL error log messages with injection-probing syntax/quoting/UNION mismatch keywords.
Bjoern Kimminich, Huntrule TeamSqlapplicationHigh151Free2017-11-27Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Flags Windows process creation where EQNEDT32.EXE is the parent, matching CVE-2017-11882 exploitation dropper behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical364Free2017-11-23