Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,201 rules
Azure AD Sign-In Logs: Account Locked After Too Many Failed Password/User ID Attempts
Flags Azure sign-in events where accounts are locked due to excessive failed logons from wrong user ID or password.
AlertIQ, Huntrule TeamAzuresigninlogsMedium308Free2021-10-10Azure Audit Logs: User registered security info (authentication method change)
Flags Azure AD audit events where a user registers new authentication security info.
AlertIQ, Huntrule TeamAzureauditlogsMedium113Free2021-10-10Linux auditd: Detect processes using --cpu-priority command-line parameter (possible miner behavior)
Alerts on Linux processes whose command line includes --cpu-priority, a common miner CPU tuning flag.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdCritical151Free2021-10-09Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
bohops, Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh143Free2021-10-08Windows Named Pipe Access to ADFS/WID Database by Uncommon Process
Alert on named pipe creation to the AD FS WID SQL query endpoint when initiated by uncommon processes.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowspipe_createdMedium122Free2021-10-08Windows Registry Writes for NetWire-Related Keys
Flags newly added Windows registry keys with paths containing \\software\\NetWire, consistent with potential NetWire-related persistence.
Christopher Peacock, Huntrule TeamWindowsregistry_addHigh163Free2021-10-07Webserver: Successful IIS shortname fuzzing scan using "~1" parameter
Alerts on successful IIS probing requests containing ~1 and ending with a.aspx using GET/OPTIONS.
frack113, Huntrule TeamWebwebserverMedium172Free2021-10-06Apache HTTP Server Web Path Traversal Attempt via Encoded Traversal Sequences (CVE-2021-41773)
Alerts on Apache requests with encoded traversal strings that return 200/301, consistent with CVE-2021-41773 probing.
daffainfo, Florian Roth, Huntrule Team—webserverHigh151Free2021-10-05Azure AD Audit Logs: User Added to Administrator Role
Flags Azure AD audit events where a user is added to an Admin/Administrator role.
Raphaël CALVET, @MetallicHack, Huntrule TeamAzureauditlogsMedium103Free2021-10-04AWS Glue Dev Endpoint Lifecycle Events (Create/Update/Delete) via CloudTrail
Flags Glue Create/Update/DeleteDevEndpoint API activity in CloudTrail that may indicate suspicious development endpoint management.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow151Free2021-10-03Linux xclip Clipboard Image Collection via Image MIME Types
Flags xclip usage that outputs image/* data from the clipboard on Linux.
Pawel Mazur, Huntrule TeamLinuxauditdLow132Free2021-10-01Windows: Suspicious Driver Installation via pnputil.exe
Flags pnputil.exe command lines indicating driver install/add actions targeting .inf files on Windows.
Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium115Free2021-09-30Windows DataSvcUtil.exe Command-Line Exfiltration Using /in:, /out:, and /uri:
Alerts on DataSvcUtil.exe runs with /in:, /out:, and /uri: parameters that may indicate data exfiltration activity.
Ialle Teixeira @teixeira0xfffff, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium101Free2021-09-30macOS firmwarepasswd Command-Line Manipulation
Alerts on firmwarepasswd usage on macOS indicating firmware password set, full, delete, or check actions.
Austin Songer @austinsonger, Huntrule TeamMacosprocess_creationMedium203Free2021-09-30Windows Prefetch File Deletion via .pf File Removal
Flags deletion of .pf files in \\Windows\\Prefetch, a possible attempt to remove execution artifacts.
Cedric MAURUGEON, Huntrule TeamWindowsfile_deleteHigh174Free2021-09-29