Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,285 rules
Linux: Base64-Encoded Shebang Patterns in Command Line
Flags Linux command lines containing Base64-encoded shebang prefixes for common shells, indicating potential encoded script execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium163Free2022-09-15Windows CLI Processes Using Common Weak or Abused Passwords
Alerts when Windows command lines include common weak or reused password values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium136Free2022-09-14Windows PowerShell Disables Windows Firewall Profiles via Set-NetFirewallProfile
Flags PowerShell commands attempting to turn off Windows Firewall profiles using Set-NetFirewallProfile.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium192Free2022-09-14Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium183Free2022-09-14Windows UAC Bypass via Elevated COM interface using ICMLuaUtil
Flags dllhost.exe parent launches tied to elevated COM /Processid GUIDs consistent with UAC bypass behavior on Windows.
Florian Roth (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-13Windows: Taskkill used to terminate ccSvcHst.exe (Symantec Endpoint Protection service impairment)
Flags Windows taskkill /F /IM ccSvcHst.exe executions that can disable Symantec Endpoint Protection services.
Ilya Krestinichev, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh381Free2022-09-13Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution
Flags Windows executions of chisel.exe with client/server tunneling and SOCKS5 reverse arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-09-13Windows Process Creation: 3proxy Proxy Server Execution
Detects execution of 3proxy.exe with local 127.0.0.1 proxy binding on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2022-09-13PowerShell Script Block Logging: Suspicious Windows Event Log Clearing Cmdlets
Flags PowerShell script blocks that call event log clearing cmdlets or ClearLog to impair Windows log visibility.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptMedium92Free2022-09-12PowerShell Enable-WindowsOptionalFeature Enables Suspicious Windows Optional Features (Windows)
Alerts on PowerShell enabling Windows optional features online for specific, potentially risky feature names.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2022-09-10PowerShell Disable-WindowsOptionalFeature -Online -FeatureName for Windows Defender features
Detects PowerShell disabling online Windows Defender features via Disable-WindowsOptionalFeature -FeatureName.
frack113, Huntrule TeamWindowsps_scriptHigh411Free2022-09-10Windows Registry Winlogon AllowMultipleTSSessions Enabled
Alerts on enabling Winlogon AllowMultipleTSSessions (DWORD 0x00000001), allowing concurrent RDP sessions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium82Free2022-09-09Windows Process Creation Recon via Event Log Query Tools and Event ID Searches
Flags Windows processes running event log query utilities and commands that search specific event IDs or dump log content.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium221Free2022-09-09Windows Schtasks.exe Scheduled Task Creation or Modification with Suspicious Schedule Types
Alerts on schtasks.exe commands that schedule tasks using ONLOGON/ONSTART/ONCE/ONIDLE with potentially malicious privilege context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh204Free2022-09-09Windows schtasks Delete All Scheduled Tasks via /tn * /delete /f
Flags schtasks.exe commands that forcibly delete all scheduled tasks on the local host using /delete /tn * /f.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-09