Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows ETW: Kernel-General resets registry hive access bits in temp hive paths
Detects ETW EventID 16 when access bits are reset for Temp \SAM or \SECURITY hives.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh322Free2017-05-15Windows DHCP Server Error: Callout DLL Failed to Load
Flags DHCP Server events showing failure to load a configured Callout DLL (Event IDs 1031/1032/1034).
Dimitrios Slamaris, @atc_project (fix), Huntrule TeamWindowssystemHigh404Free2017-05-15Windows DHCP Server Loaded Callout DLL via Registry
Flags DHCP Server events where a registry-specified callout DLL is loaded (Event ID 1033), indicating potential persistence or execution.
Dimitrios Slamaris, Huntrule TeamWindowssystemHigh81Free2017-05-15Windows Backup Catalog Deleted (Microsoft-Windows-Backup Event ID 524)
Alerts when Windows deletes the backup catalog via Microsoft-Windows-Backup Event ID 524.
Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), Huntrule TeamWindowsapplicationMedium122Free2017-05-12Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll
Alerts on WER EventID 1001 crashes where MsMpEng.exe and mpengine.dll appear in the event data.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh91Free2017-05-09Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll
Alerts on Windows Application Error EventID 1000 indicating a crash involving MsMpEng.exe and mpengine.dll.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh143Free2017-05-09Windows DNS ServerLevelPluginDll Registry Installation
Detects registry changes setting DNS ServerLevelPluginDll, which can enable malicious DNS plugin DLL loading after restart.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh365Free2017-05-08Windows: Detect dnscmd.exe setting ServerLevelPluginDll to install DNS plugin DLL
Flags dnscmd.exe DNS configuration that sets ServerLevelPluginDll, indicating potential malicious DNS server code injection.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh83Free2017-05-08Windows DNS Server error when loading ServerLevelPlugin DLL fails
Flags Windows DNS Server errors where the ServerLevelPluginDLL plugin DLL fails to load.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns-serverHigh301Free2017-05-08Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh83Free2017-04-15Firewall Alerts for C2 IP Traffic to 69.42.98.86 and 89.185.234.145
Alerts when firewall traffic involves the two specified IPs associated with presumed C2 communication.
Florian Roth (Nextron Systems), Huntrule Team—firewallHigh346Free2017-04-15Windows Security: AD user/computer backdoor via msDS-AllowedToDelegateTo and delegation attributes
Alerts on AD delegation-related attribute changes that may create credentialless account control paths.
"@neu5ron, Huntrule Team"WindowssecurityHigh188Free2017-04-13PowerShell Credential Prompt via PromptForCredential
Flags PowerShell scripts that reference "PromptForCredential", indicating credential prompt behavior in Script Block Logging.
John Lambert (idea), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh389Free2017-04-09Linux Command-Line Indicators of Equation Group Tooling
Flags execution of known suspicious Linux shell command patterns tied to Equation Group-style scripting and tooling.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High152Free2017-04-09Windows CScript and csvde Command-Line Execution Patterns Suggesting Cloud Hopper Activity
Detects cscript VBScript shell execution and csvde writing log files into C:\windows\web\.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-04-07