Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,234 rules
Windows: whoami.exe Executed by Privileged Accounts
Flags execution of whoami.exe from privileged-like accounts using Windows process creation events.
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh154Free2022-01-28Windows: Detect XORDump Utility Launch With LSASS Dump and Debug Module Switches
Alerts on xordump.exe spawning with LSASS-targeting and dump-module switches indicative of credential theft.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2022-01-28Windows File Creation of TeamViewer_Desktop.exe During Install
Alerts on Windows when TeamViewer_Desktop.exe is created, indicating potential installation or dropped remote-access binaries.
frack113, Huntrule TeamWindowsfile_eventMedium143Free2022-01-28Windows Installer Application Removed via MsiInstaller Events
Alerts on Windows Installer events indicating an application was removed via MsiInstaller.
frack113, Huntrule TeamWindowsapplicationLow131Free2022-01-28Linux auth logs: pkexec and XAUTHORITY strings indicating PwnKit (CVE-2021-4034) attempt
Alerts on Linux auth log entries with pkexec and PwnKit-related environment/session keywords consistent with CVE-2021-4034 attempts.
Sreeman, Huntrule TeamLinuxauthHigh93Free2022-01-26Windows Process Hollowing Suspected via Replaced In-Memory Image
Alerts on Windows events where a process image is replaced in memory, suggesting possible process hollowing.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Sittikorn S, Huntrule TeamWindowsprocess_tamperingMedium379Free2022-01-25Windows LOLBIN Execution From Abnormal Drive (calc, certutil, mshta, regsvr32, rundll32)
Flags Windows LOLBIN execution when process CurrentDirectory is not empty/null and contains C:\, indicating unusual launch context.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Angelo Violetti - SEC Consult '@angelo_violetti', Aaron Herman, Huntrule TeamWindowsprocess_creationMedium92Free2022-01-25Windows: RunXCmd Command-Line Execution with System or TrustedInstaller Accounts
Flags RunXCmd usage on Windows when invoked to execute commands as System or TrustedInstaller.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-01-24Windows Process Execution: NSudo (NSudo.exe/NSudoLC/NSudoLG)
Alerts on NSudo execution on Windows with privilege and integrity/elevation command-line parameters.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh327Free2022-01-24Windows Process Creation: NirCmd runasSystem CommandLine Usage
Alerts on NirCmd being used to run commands as LocalSystem based on the process command line.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh242Free2022-01-24Windows Process Creation: NirCmd Command Execution
Alerts when NirCmd.exe is launched with command-execution-oriented parameters in the process command line.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium191Free2022-01-24BlackByte ransomware Registry Set Persistence and Privilege Changes (Windows)
Alerts on BlackByte-specific Windows registry value changes to DWORD 1 across three predefined keys.
frack113, Huntrule TeamWindowsregistry_setHigh121Free2022-01-24Windows InstallUtil Execution Suspiciously Omitting /logfile Output
Alert when InstallUtil.exe runs from .NET Framework with logging parameters indicating output suppression.
frack113, Huntrule TeamWindowsprocess_creationMedium123Free2022-01-23Windows PowerShell Scripts Testing Uncommon Port Connectivity via Test-NetConnection
Detects PowerShell scripts using Test-NetConnection to reach a target on non-443/80 ports.
frack113, Huntrule TeamWindowsps_scriptMedium111Free2022-01-23Windows PowerShell: Suspicious SslStream Client Certificate Validation in Script Block
Flags PowerShell scripts referencing SslStream and client-side certificate validation during SSL client authentication.
frack113, Huntrule TeamWindowsps_scriptLow143Free2022-01-23