Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,262 rules
Windows DNS Queries to Remote Support and Remote Access Domains From Non-Browser Processes
Alert on DNS lookups for remote access service domains from non-browser executables, including RustDesk subdomains.
frack113, Connor Martin, Huntrule TeamWindowsdns_queryMedium112Free2022-07-11Azure Audit Logs: App Granted Microsoft Graph/Exchange/SharePoint/Azure AD Permissions
Alerts on Azure AD audit log entries where an app/service principal is granted delegated or app-role permissions to Microsoft services.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsHigh100Free2022-07-10Azure AD End-User Consent Blocked for Risk-Based Risky App Exceptions
Alerts when Azure end-user consent is blocked due to risk-based consent for risky apps.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsMedium135Free2022-07-10PowerShell TCP Tunnel Indicators: HttpWebRequest and TcpListener Usage (Windows
Flags PowerShell scripts referencing TcpListener/AcceptTcpClient and HttpWebRequest as potential TCP tunneling behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium162Free2022-07-08Windows: Detect Named Pipe Creation with Koh Default Names
Alerts on Windows named pipe creation with Koh default identifiers in the pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical421Free2022-07-08Proxy Log User-Agent Ending with '=' Suggesting Base64 Encoding
Alerts on proxy requests with User-Agent values ending in '=' that may indicate Base64-encoded content.
Florian Roth (Nextron Systems), Brian Ingram (update), Huntrule TeamWebproxyMedium102Free2022-07-08Windows PowerShell: Import-Module From Temp, AppData, or Public Directories
Detects PowerShell module imports (Import-Module/ipmo) from Temp, AppData, or Public directories via Script Block Logging.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium153Free2022-07-07Linux Triple Cross eBPF rootkit install commands via sudo tc on enp0s3
Flags sudo tc commands using qdisc/filter syntax and enp0s3 consistent with eBPF rootkit installer behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh142Free2022-07-05Linux process execution of execve_hijack via sudo
Alerts when /sudo spawns a process whose command line includes execve_hijack.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh91Free2022-07-05Linux eBPF Backdoor File Persistence via cron.d and sudoers.d (ebpfbackdoor)
Detects Linux creation of "ebpfbackdoor" files in cron.d/sudoers.d, indicating likely persistence via an eBPF backdoor.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxfile_eventHigh103Free2022-07-05Linux eBPF Rootkit Activity: File Creation of /tmp/rootlog
Detects creation of /tmp/rootlog on Linux, a marker used by the TripleCross rootkit to track backdoor state.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxfile_eventHigh71Free2022-07-05Linux Persistence via /etc/sudoers.d File Creation or Modification
Alerts on file changes in /etc/sudoers.d/ that may indicate persistence via sudo privilege policy.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxfile_eventMedium436Free2022-07-05Windows curl.exe Process Creation
Alerts on execution of curl.exe on Windows, which may indicate remote downloads or web requests.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow90Free2022-07-05Windows: File Download via curl.exe with -O/--remote-name or --output
Flags curl.exe with download-oriented options (-O, --remote-name, --output) to spot likely file retrieval on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2022-07-05Windows Registry Changes Disabling Windows Defender Event Log Channel
Detects registry changes that disable the Windows Defender Operational event log channel by setting its Enabled DWORD to 0.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh394Free2022-07-04