Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,235 rules
Windows Process Command Line Network Recon via nslookup LDAP SRV Query
Identifies Windows command lines running nslookup with an LDAP SRV domain controller discovery query string.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-02-07Windows Process Creation: Scheduled Task Creation via schtasks and wscript/vbscript
Alerts on Windows command lines that combine schtasks task creation with wscript running VBScript for persistence.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh91Free2022-02-07Windows Process Creation: cmd.exe Launching with PowerShell in .lnk Link Command
Alerts when explorer launches cmd.exe with command lines containing both PowerShell and a .lnk reference.
frack113, Huntrule TeamWindowsprocess_creationMedium111Free2022-02-06Windows PowerShell: DSInternals Get-ADReplAccount Enumeration
Alerts on PowerShell execution of Get-ADReplAccount with -All and -Server parameters for AD replication account enumeration.
frack113, Huntrule TeamWindowsps_scriptMedium172Free2022-02-06Windows Registry ServiceDll Hijack via Service Parameters\ServiceDll
Alerts on ServiceDll value changes for Windows services in the registry, indicating potential DLL load persistence.
frack113, Huntrule TeamWindowsregistry_setMedium141Free2022-02-04Windows: attrib.exe Executed with +s to Mark Files as System Files
Flags attrib.exe executions that include the +s switch to mark target files as system files.
frack113, Huntrule TeamWindowsprocess_creationLow60Free2022-02-04Linux auditd: systemd service file creation under systemd directories
Identifies new systemd unit file creation events under common systemd directories using auditd PATH create logs.
Pawel Mazur, Huntrule TeamLinuxauditdMedium133Free2022-02-03Windows NTLM brute force targeting workstation/device names
Alerts on NTLM EventID 8004 when WorkstationName equals common spoofed client names used in brute force attempts.
Jerry Shockley '@jsh0x', Huntrule TeamWindowsntlmMedium365Free2022-02-02Windows PowerShell: Suspicious Unblock-File to Remove Zone.Identifier
Flags PowerShell use of Unblock-File (-Path) that can remove Zone.Identifier downloaded-file metadata.
frack113, Huntrule TeamWindowsps_scriptMedium4510Free2022-02-01PowerShell Mount-DiskImage with -ImagePath to Access Disk Images
Alerts on PowerShell script blocks calling Mount-DiskImage with -ImagePath, indicative of disk-image-based payload staging.
frack113, Huntrule TeamWindowsps_scriptLow322Free2022-02-01Windows PowerShell: Suspicious Invoke-Item After Mount-DiskImage
Flags PowerShell that mounts an image, derives a drive letter, then runs content via invoke-item from that mount.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2022-02-01Windows Suspicious takeown.exe Recursive Ownership Change
Alerts when takeown.exe is run with recursive and file/folder targeting, indicating potential defense impairment via ownership changes.
frack113, Huntrule TeamWindowsprocess_creationMedium4610Free2022-01-30Windows PowerShell ScriptBlock Accessing Browser 'Login Data' Files
Flags PowerShell Copy-Item operations targeting browser Login Data credential database paths on Windows.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2022-01-30Windows File Writes of TeamViewer Session Logs
Flags Windows file creation events for TeamViewer session log artifacts like vprint.db and TVNetwork.log.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventMedium285Free2022-01-30Windows DNS Queries for TeamViewer Domains Triggered by Non-TeamViewer Image
Alerts when TeamViewer domains are resolved via DNS by a process whose image name does not include "TeamViewer".
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryMedium454Free2022-01-30