Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,203 rules
Windows Shell/Scripting Tool File Write to Suspicious Directories
Alert on file writes by common Windows shells/scripting tools to C:\PerfLogs, C:\Users\Public, or C:\Windows\Temp.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh143Free2021-11-20macOS: Process commands with trailing space in filename to evade matching
Alerts on macOS processes whose command line and image path end with a trailing space, a common filename masquerading trick.
remotephone, Huntrule TeamMacosprocess_creationLow122Free2021-11-20Windows Registry New File Association via exefile Handler (Classes\*.exefile)
Alerts on Windows registry changes creating a new file association that points to the exefile handler.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_setHigh103Free2021-11-19Linux wget POST-file Usage Indicating Data Exfiltration
Alerts on Linux wget commands using --post-file= to upload local files, indicating potential data exfiltration.
Pawel Mazur, Huntrule TeamLinuxauditdMedium266Free2021-11-18Windows MSExchange Management events indicating likely MS Exchange RCE CVE-2021-42321 exploitation
Flags Exchange management events showing Get-App cmdlet failures and unhandled InvalidCastException during CVE-2021-42321 RCE attempts.
Florian Roth (Nextron Systems), @testanull, Huntrule TeamWindowsmsexchange-managementHigh111Free2021-11-18Windows WinRAR or RAR Utility Execution from Non-Default Installation Paths
Alerts on WinRAR/RAR process execution when launched from folders outside standard WinRAR installation paths.
Florian Roth (Nextron Systems), Tigzy, Huntrule TeamWindowsprocess_creationMedium102Free2021-11-17Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)
Flags ADCS template load/update events (4898/4899) when risky EKU OIDs and enrollee-supplied subject are present.
Orlinum , BlueDefenZer, Huntrule TeamWindowssecurityHigh469Free2021-11-17Windows AD CS Certificate Template Updated/Created Enrollee Supplies Subject Flag
Alerts when AD CS certificate templates are created or updated with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT.
Orlinum , BlueDefenZer, Huntrule TeamWindowssecurityLow141Free2021-11-17Sitecore Pre-Auth RCE (CVE-2021-42237) exploitation attempts via Report.ashx POST
Alerts on successful HTTP POST traffic targeting Sitecore Reporting Report.ashx associated with CVE-2021-42237.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh113Free2021-11-17Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Alerts on scheduled task storage writes under System32\Tasks originating from suspicious process locations.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh141Free2021-11-16Windows: reg.exe Adds BitLocker Policy Registry Values
Flags reg.exe registry additions targeting BitLocker policy keys associated with configuration changes.
frack113, Huntrule TeamWindowsprocess_creationHigh396Free2021-11-15Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh257Free2021-11-15Windows Office Apps Initiate Outbound Network Connections to Non-Private IPs
Alerts when Office app processes initiate outbound TCP/HTTP(S)/mail connections to non-private IPs, excluding common private and known provider ranges.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium384Free2021-11-10Suspicious DNS Query Patterns for Cobalt Strike Beacons on Windows (Sysmon)
Alerts on Windows Sysmon DNS queries with QueryName patterns consistent with Cobalt Strike DNS beaconing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryCritical173Free2021-11-09Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Alerts on Windows file creation events for Mimikatz-related .kirbi and mimilsa.log files.
Florian Roth (Nextron Systems), David ANDRE, Huntrule TeamWindowsfile_eventCritical101Free2021-11-08