Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Security Event 4719 Audit Policy Changes indicate Windows auditing disabled
Flags Windows Event Auditing disabled indicators from Security Event ID 4719 with removed success/failure audit policy.
"@neu5ron, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"WindowssecurityLow315Free2017-11-19Windows File Events: java.exe in AppData\Roaming\Oracle\bin Path with .exe and .vbs Artifacts
Alerts on Windows file events for suspicious java*.exe placement in AppData\Roaming\Oracle\bin and .vbs files containing "Retrive".
Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsfile_eventHigh435Free2017-11-10Windows Process Creation: javaw.exe Command Line Indicates Adwind/JRAT Roaming Oracle Path
Flags command-line patterns indicating javaw.exe execution from AppData\Roaming\Oracle with java/.exe markers.
Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2017-11-10Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Flags USB device plug/unplug related Driver Frameworks User-Mode events using Windows event IDs 2003, 2100, and 2102.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver-frameworkLow3210Free2017-11-09Proxy Downloads of Executables and Documents from Suspicious Dynamic DNS Domains
Alerts when proxy traffic downloads common executable or document payload types from a curated list of dynamic DNS hostnames.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium393Free2017-11-08Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Alerts when proxy users download common malware and lure file types from hosts using suspicious TLDs.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow365Free2017-11-07Windows Named Pipe Creation Alert for Known Malicious Pipe Names
Alert on Windows named pipe creations where the PipeName matches known malware-associated pipe identifiers.
Florian Roth (Nextron Systems), blueteam0ps, elhoim, Huntrule TeamWindowspipe_createdCritical86Free2017-11-06Windows Named Pipe Creation Matching Suspected Turla Pipe Names
Alert on Windows named pipe creation when the PipeName matches Turla-associated strings.
Markus Neis, Huntrule TeamWindowspipe_createdCritical401Free2017-11-06Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Alerts on remote logons to admin-named accounts in Windows Security logs (4624, LogonType 10, Negotiate).
juju4, Huntrule TeamWindowssecurityLow304Free2017-10-29Proxy Web Requests for Flash Player Installer from Unofficial Locations
Flags proxy downloads for Flash Player installer paths when the request host is not ending in .adobe.com.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh93Free2017-10-25Windows: Detect Renamed ps.exe Executing netstat via cmd /c
Alerts on Windows executions of renamed PsTool-like ps.exe that include accept-eula and netstat via cmd.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh286Free2017-10-22Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Flags Word (WINWORD.EXE) spawning csc.exe, a suspicious execution pattern observed in some exploit chains.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical41Free2017-09-15Windows Registry Key Created: Sysinternals EULA Acceptance
Flags registry writes indicating Sysinternals EULA acceptance via a TargetObject ending with \EulaAccepted.
Markus Neis, Huntrule TeamWindowsregistry_setLow50Free2017-08-28Windows: Command-line execution using Sysinternals -accepteula flag
Alerts on Windows processes launched with the -accepteula flag, often associated with Sysinternals tool execution.
Markus Neis, Huntrule TeamWindowsprocess_creationLow72Free2017-08-28Linux JexBoss Suspicious Bash Command Launch with /dev/tcp
Flags Linux executions containing bash -c /bin/bash paired with /dev/tcp/ indicative of a reverse-shell command sequence.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High458Free2017-08-24