Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,260 rules
Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Alerts on Azure audit log events indicating an application URI (AppAddress) was modified.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh151Free2022-06-02Azure AD: Application Owner Added via Audit Log Message
Detects when an application owner is added in Azure audit logs, granting additional permissions to modify app configuration.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsMedium218Free2022-06-02Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes
Alerts on Azure audit log entries indicating updates to an application or service principal AppID URI configuration.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzureauditlogsHigh101Free2022-06-02Windows Office Child Process with Directory Traversal Patterns
Alerts on Office parent processes launching child commands containing directory traversal patterns.
Christian Burkard (Nextron Systems), @SBousseaden (idea), Huntrule TeamWindowsprocess_creationHigh122Free2022-06-02Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Alert when sdiagnhost.exe launches high-risk child processes like PowerShell or CMD, excluding selected benign-like command patterns.
Nextron Systems, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh122Free2022-06-01Windows msdt.exe Execution with Suspicious Parent Process
Alerts when msdt.exe runs under common command-and-script or utility parent processes on Windows.
Nextron Systems, Huntrule TeamWindowsprocess_creationHigh254Free2022-06-01Windows Process Creation: wfc.exe Execution for Workflow Command-line Compiler Abuse
Alerts on execution of wfc.exe by matching process image and OriginalFileName in Windows process creation logs.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsprocess_creationMedium466Free2022-06-01VisualUiaVerifyNative.exe Execution on Windows
Alerts when VisualUiaVerifyNative.exe is launched on Windows, a potential application-control bypass binary.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsprocess_creationMedium161Free2022-06-01Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Alerts on Azure sign-ins blocked by Conditional Access when requirements are not met.
Yochana Henderson, '@Yochana-H', Huntrule TeamAzuresigninlogsHigh100Free2022-06-01Azure AD Sign-in Logs: Detect ROPC Authentication Flow Use in Application Sign-ins
Flags Azure AD sign-ins where the message indicates an application is using the ROPC authentication flow.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzuresigninlogsMedium122Free2022-06-01Azure Sign-in Logs: OAuth Device Code Flow Usage Detected
Alerts on Azure sign-in events showing "Device Code" usage by applications outside expected input-constrained device contexts.
Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik', Huntrule TeamAzuresigninlogsMedium316Free2022-06-01Windows Registry: Custom URL Protocol Handler Persistence via HKCR\ Protocol Registration
Alerts on HKCR registry set activity registering a new custom URL protocol handler, excluding Microsoft-style ms- protocols.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium255Free2022-05-30Windows msdt.exe / ms-msdt Handler Arbitrary Command Execution Attempts
Alerts on Windows executions of msdt.exe with command-line indicators suggesting arbitrary command execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-05-29Windows Registry: OneDriveStandaloneUpdater.exe URL From UpdateOfficeConfig for Proxy Download
Alerts on registry settings that redirect OneDrive update URL retrieval from UpdateOfficeConfig for internet downloads.
frack113, Huntrule TeamWindowsregistry_setHigh188Free2022-05-28PowerShell: Signed UtilityFunctions.ps1 Loading Managed DLL via Proxy Execution
Flags PowerShell command lines referencing UtilityFunctions.ps1 with RegSnapin usage consistent with managed DLL proxy execution.
frack113, Huntrule TeamWindowsprocess_creationMedium111Free2022-05-28