Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,233 rules
Linux doas Command Execution Identified
Flags Linux executions of the doas utility based on process image path ending with /doas.
Sittikorn S, Teoderick Contreras, Huntrule TeamLinuxprocess_creationLow71Free2022-01-20Linux doas.conf Creation via /etc/doas.conf File Events
Alerts when /etc/doas.conf is created on a Linux host.
Sittikorn S, Teoderick Contreras, Huntrule TeamLinuxfile_eventMedium133Free2022-01-20Windows PowerShell XML Document Load Used for Execution
Flags PowerShell script blocks that use XML document loading combined with expression/command execution keywords.
frack113, Huntrule TeamWindowsps_scriptMedium3810Free2022-01-19PowerShell MsXml2.XmlHttp COM Object Instantiation
Alerts on PowerShell creating an MsXml2.XmlHttp COM object through New-Object -ComObject.
frack113, MatilJ, Huntrule TeamWindowsps_scriptMedium142Free2022-01-19Windows Registry: Disable Administrative Share Creation via LanmanServer Parameters
Flags registry writes that disable Windows administrative share auto-creation under LanmanServer parameters.
frack113, Huntrule TeamWindowsregistry_setMedium151Free2022-01-16Windows msiexec.exe Quiet MSI Installation with Installer Arguments
Flags msiexec.exe launched with -q plus MSI installer switches, indicating quiet installation behavior in Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationMedium70Free2022-01-16Windows: Suspicious msiexec.exe Command-Line Writes Install Logs with /Y
Alerts on suspicious msiexec.exe executions using the /Y argument that are not consistent with common installer locations.
frack113, Huntrule TeamWindowsprocess_creationMedium437Free2022-01-16Windows DISM Online Disable-Feature via DismHost.exe or Dism.exe
Flags Windows DISM/DismHost executions using /Online and /Disable-Feature, a common defense-impairment technique.
frack113, Huntrule TeamWindowsprocess_creationMedium144Free2022-01-16PowerShell ScriptBlock Logging: Set-MpPreference disables Windows Defender scanning or allows threats
Alert on PowerShell Set-MpPreference usage that disables Defender scanning/monitoring or sets threat default actions to Allow.
frack113, elhoim, Tim Shelton (fps, alias support), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh342Free2022-01-16Windows: Deletion of TeamViewer log files
Alerts on deletion of TeamViewer *.log files on Windows, excluding deletions performed by svchost.exe.
frack113, Huntrule TeamWindowsfile_deleteLow161Free2022-01-16Windows msiexec.exe Initiates Outbound HTTP(S) Connection on Port 80/443
Alerts when msiexec.exe starts outbound connections to ports 80 or 443, indicating potential remote package retrieval.
frack113, Huntrule TeamWindowsnetwork_connectionLow90Free2022-01-16Windows rmdir Directory Removal via cmd.exe Execution
Monitors cmd.exe process creation where rmdir is used with /s and/or /q to delete directories and reduce forensic artifacts.
frack113, Huntrule TeamWindowsprocess_creationLow70Free2022-01-15Windows del/erase Command-Line File Deletion via cmd.exe
Flags cmd.exe executions running del/erase for file removal, including common flags like /f, /s, and /q.
frack113, Huntrule TeamWindowsprocess_creationLow229Free2022-01-15Windows PowerShell: Start-Process with -PassThru and -FilePath
Alerts on PowerShell Start-Process calls that include -PassThru and -FilePath, based on ScriptBlockText matches.
frack113, Huntrule TeamWindowsps_scriptMedium131Free2022-01-15Windows PowerShell ScriptBlock Use of Remove-Item to Delete Files or Folders
Alerts on PowerShell ScriptBlockText containing Remove-Item/del/rm/rd-style -Path deletion commands.
frack113, Huntrule TeamWindowsps_scriptLow60Free2022-01-15