Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,207 rules
Azure Sign-in Auth Interruption: DeviceAuthenticationRequired/Failed and External Security Challenge
Alerts on Azure sign-in authentication interruptions tied to device authentication and external security challenge failures.
Austin Songer @austinsonger, Huntrule TeamAzuresigninlogsMedium162Free2021-11-26Azure AuditLogs: Privileged role assignment to user access admin
Flags Azure AuditLogs events where a user is assigned to User Access Administrator, enabling full subscription management.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsHigh163Free2021-11-26Azure Activity Logs: Authorization ElevateAccess Grants Subscription-Level Management
Alerts on Azure Activity Log authorization elevation actions that can grant access to manage all subscriptions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsHigh122Free2021-11-26Windows Process Execution of Extexport.exe Suggesting Potential DLL Sideloading
Flags execution of Extexport.exe on Windows, which can be abused to side-load DLLs via crafted command lines.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium40Free2021-11-26Windows PowerShell Clears Console History via Clear-History
Flags PowerShell attempts to clear or delete console/PSReadline command history to hinder command forensics.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptHigh60Free2021-11-25GCP Kubernetes audit events: Admission webhook configuration creates/updates
Flags GCP Kubernetes audit events indicating mutating/validating admission webhook configuration create/patch/replace activity.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium131Free2021-11-25Azure Activity Logs: Kubernetes AdmissionRegistration webhook configuration writes
Flags Azure activity log events writing Kubernetes admission webhook configurations (mutating or validating), indicating potential cluster request interception.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium152Free2021-11-25Windows: Rundll32 Loading shell32.dll via Control_RunDLL from User/Temp Paths
Alerts on rundll32.exe loading shell32.dll with Control_RunDLL from AppData/Temp/user paths.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2021-11-24Windows CertReq -Post Download Attempt via HTTP
Flags certreq.exe executions using -Post -config and HTTP content retrieval indicators.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh349Free2021-11-24Windows bash.exe Launched with -c for Indirect Inline Command Execution
Alerts on Windows processes starting bash.exe with -c, indicating inline command execution.
frack113, Huntrule TeamWindowsprocess_creationMedium421Free2021-11-24Windows: aspnet_compiler.exe Execution Detection
Detects execution of aspnet_compiler.exe from Windows .NET Framework directories, which can be abused to compile and run C#.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2021-11-24Windows DNS Queries Triggered by DesktopAppInstaller AppInstaller.EXE
Identifies DNS lookups performed by Windows AppInstaller.EXE when initiating ms-appinstaller package installation from a URL.
frack113, Huntrule TeamWindowsdns_queryMedium335Free2021-11-24Windows PsExec/PAExec Command-Line Flags Escalating to LOCAL SYSTEM
Flags in PsExec/PAExec command lines requesting LOCAL SYSTEM execution are matched via process creation command-line telemetry.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2021-11-23Windows process access to LSASS.exe with suspicious GrantedAccess flags
Alerts on process access attempts to lsass.exe with GrantedAccess rights commonly linked to credential theft behavior.
Florian Roth, Roberto Rodriguez, Dimitrios Slamaris, Mark Russinovich, Thomas Patzke, Teymur Kheirkhabarov, Sherif Eldeeb, James Dickenson, Aleksey Potapov, oscd.community, Huntrule TeamWindowsprocess_accessMedium402Free2021-11-22GCP Kubernetes CronJob or Job Creation via gcp.audit
Flags GCP audit events where Kubernetes batch Job/CronJob API methods indicate CronJob or Job execution setup.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium181Free2021-11-22