Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Kerberos Service Tickets Requesting RC4 Encryption (EventID 4769)
Flags Windows Kerberos service ticket requests using RC4 encryption while excluding '$' machine/service accounts.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium275Free2017-02-06Windows Event Logs: Mimikatz Keyword Indicators
Detects Mimikatz-related keywords in Windows event logs while filtering Sysmon EventID 15 to limit noise.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindows—High427Free2017-01-10Windows Event Log Cleared (Microsoft-Windows-Eventlog EventID 104)
Alerts when Windows event logs are cleared, based on Microsoft-Windows-Eventlog Event ID 104 from System telemetry.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemMedium181Free2017-01-10Windows Security and Eventlog Cleared via Event IDs 517 or 1102
Flags Windows event log clearing using Security Event ID 517 and Microsoft-Windows-Eventlog Event ID 1102.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh368Free2017-01-10Windows Webshell Recon Command-Line Keywords via Web Server Processes
Flags Windows process chains where web server parents spawn reconnaissance- and execution-related command lines indicative of webshell activity.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson, Huntrule TeamWindowsprocess_creationHigh307Free2017-01-01Windows WerFault Access to lsass.exe Indicative of Credential Dumping Attempts
Alert on WerFault.exe gaining broad access to lsass.exe, consistent with credential dumping attempts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh183Free2012-06-27