Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
OpenCanary: MSSQL Windows Authentication Login Attempt (Logtype 9002)
Alerts on OpenCanary MSSQL events where Windows Authentication login attempts are observed.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh151Free2024-03-08OpenCanary MSSQL SQLAuth Login Attempt Detected (logtype 9001)
Flags MSSQL SQLAuth login attempts recorded by OpenCanary for credential-access style activity.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh112Free2024-03-08OpenCanary HTTPPROXY Login Attempt Shows Proxied Page Access
Alerts on OpenCanary HTTPPROXY events indicating a proxy request for another page.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh283Free2024-03-08OpenCanary: HTTP Form POST Login Attempt Observed on Port Service
Alerts on OpenCanary HTTP Form POST events indicating a login attempt to an exposed service.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh315Free2024-03-08OpenCanary application telemetry: HTTP GET requests received by monitored service
Alerts when OpenCanary logs an HTTP GET request to a monitored service endpoint.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh162Free2024-03-08OpenCanary Git Service: Git Clone Request Observed
Flags OpenCanary Git service logs showing a Git clone request, indicating possible repository access attempts.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh81Free2024-03-08OpenCanary FTP Login Attempt on Port 2000
Flags OpenCanary application events indicating an FTP login attempt on a monitored node.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh131Free2024-03-08Windows Kerberos KDC Key Distribution Failure: No Suitable Encryption Key or Unsupported EType
Flags KDC TGS generation failures where no suitable encryption key intersects or the requested encryption type is unsupported.
"@SerkinValery, Huntrule Team"WindowssystemLow91Free2024-03-07Windows AD CS Denied Certificate Enrollment Requests (Event ID 53)
Alerts on CA-side denied certificate enrollment attempts in Windows via Microsoft-Windows-CertificationAuthority Event ID 53.
"@SerkinValery, Huntrule Team"WindowssystemLow364Free2024-03-07GitHub Secret Scanning Disabled for Enterprise or Repository
Flags GitHub audit events that disable secret scanning for an enterprise or repository, reducing exposed secret detection.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditHigh367Free2024-03-07GitHub Audit: Secret Scanning Push Protection Disabled
Alerts on GitHub audit log events where secret scanning push protection is disabled for org, repo, or custom patterns.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditHigh451Free2024-03-07GitHub Audit: Secret Scanning Push Protection Bypass Event Detected
Triggers on GitHub audit events indicating a secret scanning push protection bypass attempt.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditLow215Free2024-03-07Windows Process Creation: rundll32 Shell32 Control_RunDLL Executes .CPL from User Temp
Detects rundll32 Shell32 Control_RunDLL launching a .CPL from user Temp, a stealthy execution path.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh92Free2024-03-07Windows Registry: SentinelOne Scan Context Menu Command Tampering by Non-SentinelOne Process
Alerts on registry modifications to SentinelOne scan context menu command entries not matching SentinelOne’s expected binary.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium72Free2024-03-06Windows Shell Context Menu Registry Command Tampering
Flags Windows registry modifications that add or alter shell context menu commands under Classes\shell\command.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow80Free2024-03-06