Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows PFX File Creation From File Events
Flags Windows file events where a .pfx (certificate + private key) is created, excluding a few common benign locations.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventLow50Free2020-05-02AWS CloudTrail EC2 CreateInstanceExportTask Failure
Flags failed EC2 VM export task creation events in AWS CloudTrail to surface potential instance data extraction attempts.
Diogo Braz, Huntrule TeamAwscloudtrailLow101Free2020-04-16Successful Windows Account Logon via WMI (4624 with WmiPrvSE.exe)
Flags successful 4624 logons tied to WmiPrvSE.exe, indicating WMI-driven authentication on Windows.
Thomas Patzke, Huntrule TeamWindowssecurityLow83Free2019-12-04Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Flags Windows Event ID 6416 entries where a DiskDrive/USB Mass Storage Device is detected as connected.
Keith Wright, Huntrule TeamWindowssecurityLow96Free2019-11-20Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationLow71Free2019-10-24Windows hh.exe Execution Triggered by .chm Command Line
Flags hh.exe being executed with a command line referencing a .chm file on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community, Huntrule TeamWindowsprocess_creationLow93Free2019-10-24Windows Security 4697: TAP Driver Service Installation (tap0901)
Alerts on Windows Security EID 4697 service installation events for TAP driver files containing "tap0901."
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowssecurityLow133Free2019-10-24Linux auditd: dd overwrites a file using /dev/null or /dev/zero
Flags dd command lines that overwrite files by sourcing data from /dev/null or /dev/zero.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdLow92Free2019-10-23Windows Raw Disk Access by Uncommon Process Paths
Alerts on Windows raw disk access by processes from uncommon or suspicious locations.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsraw_access_threadLow51Free2019-10-22Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow335Free2019-10-21Windows Rar.exe Files Added to Archive Activity
Alerts when Windows rar.exe is used to add files to an archive using the " a " command-line pattern.
Timur Zinniatullin, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationLow169Free2019-10-21Windows: net.exe used to start a service with the start flag
Identifies Windows processes using net.exe/net1.exe with ' start ' to start services.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21Windows Process: File Association Changes via assoc Command
Alerts on cmd.exe launches running the assoc command to modify Windows default file associations.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21Linux System Owner or User Discovery via Common Utility Execution
Flags execution of Linux user/system identification utilities such as whoami and id.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow376Free2019-10-21Linux: Detect execution of tcpdump or tshark with interface (-i) capture option
Alerts on tcpdump or tshark executions on Linux where an interface flag is present, consistent with network sniffing.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow438Free2019-10-21