Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,419 rules
Windows Process Execution Matches Griffon Malicious Command-Line Pattern
Alerts on Windows process command lines containing a temp staging path plus jscript execution indicators and a .txt target.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical172Free2023-03-09Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh197Free2023-03-08Windows cmd.exe Reads Input from STDIN Using '<' Redirection
Flags cmd.exe invocations with '<' in the command line, indicating stdin/input redirection.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium422Free2023-03-07Linux Auditd: Unix Shell Configuration File Modification
Alerts when shell startup or login configuration files (system or user) are modified on Linux.
Peter Matkovski, IAI, Huntrule TeamLinuxauditdMedium183Free2023-03-06Linux firewall rule deletion via iptables, firewall-cmd, ufw, or nft
Flags EXECVE activity that removes Linux firewall rules using iptables, firewall-cmd, ufw, or nft.
IAI, Huntrule TeamLinuxauditdMedium3110Free2023-03-06Windows: Stop a Service with sc.exe via Process Creation (sc.exe stop)
Identifies sc.exe executions that include 'stop' to stop Windows services based on process creation and command line.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow192Free2023-03-05Windows PowerShell Stop-Service Used to Stop a Service
Flags PowerShell executions that include the Stop-Service cmdlet to stop a Windows service.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow131Free2023-03-05Windows: Service stop activity via net.exe command line
Flags Windows processes running net.exe/net1.exe with a command line containing ' stop ' to stop a service.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow100Free2023-03-05Windows: Root Certificate Added Using certutil.exe -addstore
Flags certutil.exe executions that use -addstore with root-related parameters to install a certificate.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationMedium389Free2023-03-05Windows: Root Certificate Installation via CertMgr.EXE (/add root)
Flags CertMgr.EXE used to add a root certificate on Windows by matching /add and root in the command line.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationMedium121Free2023-03-05Windows PowerShell Set-Service StartupType Change to Disabled or Manual
Alerts on PowerShell Set-Service commands changing a service startup type to Disabled or Manual on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium227Free2023-03-04Windows whoami.exe Execution With /FO CSV or Output Redirection
Detects whoami.exe runs that request CSV output or indicate output redirection for saved results.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2023-02-28Windows whoami.exe Group Membership Reconnaissance via /groups Flag
Flags whoami.exe runs that use the /groups option to enumerate current user group memberships and SIDs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-02-28Windows sc.exe Service Security Descriptor Tampering (sdset)
Detects sc.exe executions using sdset to modify service security descriptors, enabling stealthy service tampering.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-02-28Windows sc.exe Service Security Descriptor Changes via sdset
Alerts on sc.exe sdset activity that modifies a service security descriptor to grant access to targeted principals.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-02-28