Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,234 rules
Windows PowerShell: WebRequest User-Agent Modification in ScriptBlockText
Detects PowerShell scripts that make web requests and set a custom -UserAgent value.
frack113, Huntrule TeamWindowsps_scriptMedium122Free2022-01-23Windows Office Macro File Creation Triggered by Script/LOLBin Parent Process
Alerts when macro-enabled Office files are created by common Windows script execution processes.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh143Free2022-01-23Windows Office Macro File Creation from Browser or Email Client
Flags Windows creation of macro-enabled Office files (.docm/.xlsm/.pptm) initiated by common browsers or email clients.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow187Free2022-01-23Windows Office Macro File Creation via Office Applications
Alerts on creation of macro-enabled Office documents/templates by Office apps on Windows, excluding Office temporary files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow161Free2022-01-23Windows curl.exe Execution Using Custom User-Agent Flags
Flags Windows process launches of curl.exe with -A/--user-agent parameters to set a custom user agent.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2022-01-23Windows Registry: Internet Settings Zone and Cache-related Key Modifications
Flags registry writes to Windows Internet Settings-related keys that can be abused to alter zone trust or store persistence data.
frack113, Huntrule TeamWindowsregistry_setLow133Free2022-01-22Windows Registry Set to Hide File Extensions via Explorer Advanced Keys
Flags registry changes under Explorer Advanced that hide file extensions by setting specific DWORD values.
frack113, Huntrule TeamWindowsregistry_setMedium168Free2022-01-22Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Flags Windows registry changes to IE ZoneMap domain entries that alter security zone assignments for targeted domains.
frack113, Huntrule TeamWindowsregistry_setMedium2910Free2022-01-22Radmin Viewer Utility Execution on Windows (Process Creation)
Alerts when Radmin Viewer (Radmin.exe) is launched, based on process metadata in Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationMedium195Free2022-01-22Windows Network Connection Initiated by IMEWDBLD.EXE
Alerts when IMEWDBLD.EXE initiates a network connection on Windows.
frack113, Huntrule TeamWindowsnetwork_connectionHigh151Free2022-01-22Linux Auditd: Stop Firewalld, iptables, or UFW Services
Detects stopping firewall services (firewalld/iptables/ufw) on Linux via auditd service-stop events.
Pawel Mazur, Huntrule TeamLinuxauditdHigh163Free2022-01-22Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color
Alerts on colorcpl.exe creating files in C:\Windows\System32\spool\drivers\color\ with suspicious target filenames.
frack113, Huntrule TeamWindowsfile_eventHigh166Free2022-01-21Windows Kerberoasting Initial Query: Successful 4769 RC4 Service Requests with Filters
Collects successful Windows 4769 RC4 service-ticket requests while excluding krbtgt and computer/service account patterns for kerberoasting triage.
"@kostastsale, Huntrule Team"WindowssecurityMedium343Free2022-01-21Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Detects AdvancedRun execution where /RunAs is set to specific high-privilege IDs in the process command line.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-01-20Windows PUA AdvancedRun.exe Execution
Detects AdvancedRun.exe executions on Windows with /Run and /RunAs style command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-01-20