Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,202 rules
PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Flags PowerShell script block text indicating WindowStyle set to Hidden, suggesting concealed execution.
frack113, Tim Shelton (fp AWS), Huntrule TeamWindowsps_scriptMedium215Free2021-10-20PowerShell: Set-ExecutionPolicy to Unrestricted or Bypass
Alerts when PowerShell sets execution policy to Unrestricted or bypass, indicating weakened script execution controls.
frack113, Huntrule TeamWindowsps_scriptMedium163Free2021-10-20Windows Registry: Clearing RDP Client Connection History via MRU and Server Keys Deletion
Flags registry deletions that remove Windows RDP client connection history from Terminal Server Client MRU and Servers keys.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh437Free2021-10-19Linux Network Connection to /bin/bash via Reverse Shell Pattern
Alerts on /bin/bash network connections to non-local destination IPs, consistent with reverse shell behavior.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionCritical131Free2021-10-16Linux Process Creation Webshell Tooling: Web Server Child Processes Running System Commands
Detects web server processes spawning Linux command-line tools commonly used for host discovery or persistence.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh173Free2021-10-15Linux dd Command Overwrite or Deletion via of= and input redirection
Flags Linux dd executions that use of= with /dev/zero or /dev/null, consistent with file overwrite or deletion attempts.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamLinuxprocess_creationLow142Free2021-10-15Linux Clipboard Data Collection via xclip -sel clip -o
Alerts on Linux processes running xclip to output clipboard content using -sel clip -o.
Pawel Mazur, Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamLinuxprocess_creationLow3710Free2021-10-15Linux Syslog Clearing or Removal Using System Utilities
Alert on Linux commands that clear, delete, truncate, or redirect /var/log/syslog or rotate/vacuum journald logs.
Max Altgelt (Nextron Systems), Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamLinuxprocess_creationHigh244Free2021-10-15Linux Cron Directory File Creation via File Events
Flags new Linux cron-related files created under standard cron directories, excluding a few known benign paths.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamLinuxfile_eventLow218Free2021-10-15GCP Cloud SQL Database Modified or Deleted via Audit API
Alerts on Cloud SQL instance create/delete and user update/delete events in GCP audit logs.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium183Free2021-10-15Windows PowerShell: Disable Windows Firewall Profile via Set-NetFirewallProfile
Flags PowerShell commands that disable one or more Windows Firewall profiles via Set-NetFirewallProfile -Enabled $false.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptMedium132Free2021-10-12OneLogin: Detect API user account lock or suspension events
Flags OneLogin API events indicating a user account was locked or suspended.
Austin Songer @austinsonger, Huntrule TeamOneloginonelogin.eventsLow133Free2021-10-12OneLogin: User Assumes Another Account via Event Type 3
Alerts on OneLogin events indicating a user assumed another user account via event_type_id 3.
Austin Songer @austinsonger, Huntrule TeamOneloginonelogin.eventsLow161Free2021-10-12Azure Sign-in Logs: Conditional Access Blocks User Token Issuance (ResultType 53003)
Flags Azure sign-in attempts blocked by Conditional Access due to token issuance denial.
AlertIQ, Huntrule TeamAzuresigninlogsMedium4210Free2021-10-10Azure Sign-in Log MFA Interrupted via Strong Auth Failures
Identifies Azure sign-ins that fail during strong/MFA authentication, suggesting blocked credential attempts.
AlertIQ, Huntrule TeamAzuresigninlogsMedium235Free2021-10-10