Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,454 rules
Windows: Suspicious HTA Startup Folder Creation by FoxitPDFReader.exe
Alerts on FoxitPDFReader.exe creating .hta files in the Startup Programs folder, which can indicate persistence.
Gregory, Huntrule TeamWindowsfile_eventHigh1810Free2023-10-11Windows ScreenConnect RMM System Command Execution via cmd.exe
Flags cmd.exe launched by ScreenConnect.ClientService.exe with a TEMP\ScreenConnect command-line path.
Ali Alwashali, Huntrule TeamWindowsprocess_creationLow131Free2023-10-10Windows: ScreenConnect Temporary File Creation in ConnectWiseControl Temp
Flags file writes to ScreenConnect’s ConnectWiseControl\Temp staging directory from ScreenConnect.WindowsClient.exe.
Ali Alwashali, Huntrule TeamWindowsfile_eventLow82Free2023-10-10Windows Application: ScreenConnect RMM File Transfer Activity (Event 201)
Flags ScreenConnect RMM file transfer events on Windows based on provider name, Event ID 201, and transfer action text.
Ali Alwashali, Huntrule TeamWindowsapplicationLow164Free2023-10-10Windows ScreenConnect Remote Command Execution (EventID 200)
Detects ScreenConnect command execution on Windows by matching EventID 200 with an 'Executed command of length' message.
Ali Alwashali, Huntrule TeamWindowsapplicationLow133Free2023-10-10Windows Process Creation: CLI CommandLine References NTFS ::$index_allocation Stream
Flags Windows CLI commands referencing the NTFS ::$index_allocation stream for potential hidden directory activity.
Nasreddine Bencherchali (Nextron Systems), Scoubi (@ScoubiMtl), Huntrule TeamWindowsprocess_creationMedium121Free2023-10-09Windows Hidden Directory Creation Using NTFS $INDEX_ALLOCATION Stream
Alerts on Windows file events creating hidden NTFS content using the '::$index_allocation' alternate stream.
Scoubi (@ScoubiMtl), Huntrule TeamWindowsfile_eventMedium389Free2023-10-09Windows Kerberos KDC: Certificate used without strong user mapping
Alerts on Windows KDC certificate validation events lacking strong certificate-to-user mapping (Event 39/41).
"@br4dy5, Huntrule Team"WindowssystemMedium244Free2023-10-09Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary
Flags Windows process executions that match renamed VS Code tunnel invocation patterns and related internal service startup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2023-09-28Windows Service Registry Key ReadControl Access (Event ID 4663)
Flags READ_CONTROL access requests to service registry keys (\SYSTEM\ControlSet\Services\) via Windows Security Event 4663.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowssecurityLow153Free2023-09-28AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
Detects CloudTrail identity center events that associate or change the external identity provider configuration.
Michael McIntyre @wtfender, Huntrule TeamAwscloudtrailHigh122Free2023-09-27Windows Registry Scheduled Task Cache Key Creation Detection
Flags registry event activity under Scheduled TaskCache indicating scheduled task creation or updates on Windows.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowsregistry_eventLow80Free2023-09-27Windows Scheduled Task File Creation Activity (File Event)
Flags file creation under Windows scheduled task directories that may indicate new scheduled task persistence.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowsfile_eventLow80Free2023-09-27Windows: AddInUtil.exe LoLBin Executed from Non-Standard Directory
Alerts when AddInUtil.exe (AddInUtil.exe) runs from an uncommon directory path on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium184Free2023-09-18Windows Process Creation: Uncommon AddInUtil.exe Use of AddInRoot/PipelineRoot Paths
Alerts on AddInUtil.exe runs where AddInRoot/PipelineRoot command-line paths deviate from common VSTA locations.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationMedium259Free2023-09-18