Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Service Install (Event ID 7045) for srservice, ipvpn, hkmsvc
Alerts on Windows service creation events (7045) for srservice, ipvpn, and hkmsvc service names.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh111Free2017-03-31Windows Service Creation: ServiceName javamtsup (Event ID 4697)
Flags Windows Security Event 4697 when a service named "javamtsup" is installed, indicating potential persistence.
Florian Roth (Nextron Systems), Daniil Yugoslavskiy, oscd.community (update), Huntrule TeamWindowssecurityCritical112Free2017-03-27Linux Log File Alerts for Suspicious Messages
Generates alerts when Linux log text contains suspicious keywords indicating possible network, service, or logging disruption.
Florian Roth (Nextron Systems), Huntrule TeamLinux—Medium41Free2017-03-25PowerShell downgrade indicators via EngineVersion=2. and HostVersion !=2. (Windows)
Detects PowerShell version mismatches that may indicate a downgrade attempt using EngineVersion vs HostVersion telemetry.
Florian Roth (Nextron Systems), Lee Holmes (idea), Harish Segar (improvements), Huntrule TeamWindowsps_classic_startMedium398Free2017-03-22Windows Registry UAC Bypass via Event Viewer Command Key (mscfile shell open command)
Alerts on registry changes to the mscfile shell open command key consistent with an Event Viewer UAC bypass technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh131Free2017-03-19Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-03-19Windows Network Connections to Uncommon Ports (8080, 8888)
Flags Windows-initiated connections to ports 8080/8888 excluding private/local IPs and Program Files binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium147Free2017-03-19Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh83Free2017-03-19Windows network connection from process running in suspicious or uncommon file paths
Alerts on Windows network connections initiated by processes executing from suspicious or uncommon directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh209Free2017-03-19Windows UAC Bypass Indicator via sdclt Registry Key Manipulation
Alerts on registry set activity consistent with sdclt-related UAC bypass key manipulation.
Omer Yampel, Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh92Free2017-03-17Windows Security: Local Administrators Group Membership Change (Event 4732)
Flags Windows Event 4732 where a user is added to the local Administrators group.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium335Free2017-03-14Linux Log Shellshock Expression Pattern Matching
Identifies Shellshock-style function-body expressions in Linux log data via keyword string matches.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High309Free2017-03-14Windows PowerShell Web Access User-Agent Containing "WindowsPowerShell/" (Proxy Logs)
Alerts when proxy traffic shows a User-Agent containing "WindowsPowerShell/", consistent with PowerShell web access.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium131Free2017-03-13Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains
Finds proxy traffic requesting executable or script/doc payloads from hosts with suspicious TLDs not in the whitelist.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow62Free2017-03-13Windows Network Connections Initiated by PowerShell (powershell.exe or pwsh.exe)
Flags outbound network connections initiated by PowerShell on Windows, excluding common local and private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionLow80Free2017-03-13