Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows Security Event 4616 for System Time Changes by Non-Service Accounts
Flags Windows Event 4616 system time changes when made by processes outside svchost.exe and common virtualization agents.
"@neu5ron, Huntrule Team"WindowssecurityLow82Free2019-02-05Windows schtasks.exe Scheduled Task Creation by Non-Microsoft Office Integration
Alerts on schtasks.exe /create executions indicating scheduled task creation, with exclusions for Office integrator-related cases.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow237Free2019-01-16Windows Process Creation: Execution of Net.exe or Net1.exe
Alerts on execution of net.exe/net1.exe with common net subcommands via Windows process creation and command-line telemetry.
Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements), Huntrule TeamWindowsprocess_creationLow40Free2019-01-16Windows NTLM authentication events (Event ID 8002)
Alerts on Windows NTLM authentication occurrences based on Event ID 8002 from Microsoft-Windows-NTLM/Operational.
Florian Roth (Nextron Systems), Huntrule TeamWindowsntlmLow2010Free2018-06-08Windows Process Creation with taskmgr.exe as Parent Process
Flags process creation where taskmgr.exe is the parent, excluding a few known benign child process images.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow92Free2018-03-13Windows Security Event 4719 Audit Policy Changes indicate Windows auditing disabled
Flags Windows Event Auditing disabled indicators from Security Event ID 4719 with removed success/failure audit policy.
"@neu5ron, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"WindowssecurityLow345Free2017-11-19Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Flags USB device plug/unplug related Driver Frameworks User-Mode events using Windows event IDs 2003, 2100, and 2102.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver-frameworkLow3410Free2017-11-09Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Alerts when proxy users download common malware and lure file types from hosts using suspicious TLDs.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow395Free2017-11-07Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Alerts on remote logons to admin-named accounts in Windows Security logs (4624, LogonType 10, Negotiate).
juju4, Huntrule TeamWindowssecurityLow314Free2017-10-29Windows Registry Key Created: Sysinternals EULA Acceptance
Flags registry writes indicating Sysinternals EULA acceptance via a TargetObject ending with \EulaAccepted.
Markus Neis, Huntrule TeamWindowsregistry_setLow80Free2017-08-28Windows: Command-line execution using Sysinternals -accepteula flag
Alerts on Windows processes launched with the -accepteula flag, often associated with Sysinternals tool execution.
Markus Neis, Huntrule TeamWindowsprocess_creationLow92Free2017-08-28Windows: PsExec Service File Creation via PSEXESVC.exe Written to Disk
Flags Windows file creation of \PSEXESVC.exe, indicating potential PsExec service deployment for remote execution.
Thomas Patzke, Huntrule TeamWindowsfile_eventLow152Free2017-06-12Windows Named Pipe Creation for PsExec Default Pipe
Alerts on creation of the default PsExec named pipe (\\PSEXESVC) using Windows named pipe creation telemetry.
Thomas Patzke, Huntrule TeamWindowspipe_createdLow80Free2017-06-12Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains
Finds proxy traffic requesting executable or script/doc payloads from hosts with suspicious TLDs not in the whitelist.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow62Free2017-03-13Windows Network Connections Initiated by PowerShell (powershell.exe or pwsh.exe)
Flags outbound network connections initiated by PowerShell on Windows, excluding common local and private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionLow80Free2017-03-13