Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,194 rules
Linux auditd: Hidden file or directory creation via leading-dot paths in execve
Alerts on Linux process executions creating or modifying dot-prefixed (hidden) files/directories.
Pawel Mazur, Huntrule TeamLinuxauditdLow152Free2021-09-06Azure AD Domain Federation Settings Modified via Audit Logs
Alerts when federation settings on an Azure AD domain are modified, indicating potential identity trust tampering.
Austin Songer, Huntrule TeamAzureauditlogsMedium143Free2021-09-06Linux Audio Capture via arecord and ecasound (auditd execve and memfd_create)
Detects Linux execution of arecord for audio capture and ecasound using memfd_create for in-memory data handling.
Pawel Mazur, Milad Cheraghi, Huntrule TeamLinuxauditdLow367Free2021-09-04Linux auditd System Information Discovery via uname, uptime, lsmod, hostname, env, and release file reads
Triggers on auditd events showing host enumeration commands and system identity file access on Linux.
Pawel Mazur, Huntrule TeamLinuxauditdLow173Free2021-09-03Azure Audit Logs: Service Principal Removed via Remove service principal
Flags Azure audit log events where a service principal is removed from Entra ID.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium236Free2021-09-03Azure Audit Logs: Owner Removed From Application or Service Principal
Alerts on Azure audit log activity indicating an owner was removed from an application or service principal.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium163Free2021-09-03Azure Audit Logs: Device No Longer Managed or Compliant
Alerts on Azure device audits indicating the device is no longer managed or compliant.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium175Free2021-09-03Azure Audit Logs: Application Deletion (Delete/Hard Delete) Detected
Flags Azure audit events where an application (or administrative unit) is deleted, including hard deletes.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium102Free2021-09-03Azure Activity Logs: Device or Device Configuration Modified or Deleted
Flags Azure audit events indicating device or device configuration updates or deletions.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium81Free2021-09-03PowerShell ScriptBlock launching redirected comspec to Alternate Data Stream via '>'
Flags PowerShell script blocks using Start-Process with comspec and " > " redirection consistent with ADS-style file hiding.
frack113, Huntrule TeamWindowsps_scriptMedium93Free2021-09-02Windows Kerberos TGT Request with AD CS Certificate Thumbprint Anomalies (EventID 4768)
Identifies unusual certificate-associated Kerberos TGT (4768) requests targeting computer accounts on Windows.
Mauricio Velazco, Michael Haag, Huntrule TeamWindowssecurityHigh82Free2021-09-02Azure Audit Logs: Service Principal Created via Add service principal
Alerts on Azure audit log events that add a new service principal.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium121Free2021-09-02Azure Network Firewall Policy Modified or Deleted via Activity Logs
Alerts on Azure Activity Log operations that modify or delete Network Firewall Policies.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium279Free2021-09-02Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowswmi_eventHigh364Free2021-09-01Windows Process Creation: Execution CommandLines Involving NTFS Alternate Data Streams
Alerts on Windows executions whose command lines reference NTFS Alternate Data Streams combined with specific file-data tools.
frack113, Huntrule TeamWindowsprocess_creationMedium2310Free2021-09-01