Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,191 rules
Microsoft Cloud App Security: Alerts for Successful Activity from Infrequent Countries
Alerts on successful Microsoft Cloud App Security anomaly events for activity from countries not recently visited by your users.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium264Free2021-08-23M365 Threat Management: Activity from Anonymous Proxy IP Addresses
Alerts when Microsoft 365 threat management reports successful activity from IPs marked as anonymous proxies.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium123Free2021-08-23Microsoft Cloud App Security Activity by Terminated Azure AD User
Alerts on successful "Activity performed by terminated user" events where a terminated Azure AD account still shows activity.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium81Free2021-08-23Microsoft Cloud App Security: Activity from Microsoft Threat Intelligence Risky IPs
Alert on successful Cloud App Security activity events tied to IPs marked risky by Microsoft Threat Intelligence.
Austin Songer @austinsonger, Huntrule TeamM365threat_detectionMedium2810Free2021-08-23Google Workspace Admin API: User Granted Admin Privileges
Flags Google Workspace audit events where a user is granted delegated or admin privileges in the tenant.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium133Free2021-08-23Google Workspace Admin API Client Authorization Granted to Service Accounts
Identifies Google Workspace domain-level authorization of an API client via admin.googleapis.com audit events.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium142Free2021-08-23Windows: Suspicious explorer.exe Child Process Spawned by RazerInstaller.exe
Flags explorer.exe spawned by RazerInstaller.exe when the installer runs at System/high integrity.
Florian Roth (Nextron Systems), Maxime Thiebaut, Huntrule TeamWindowsprocess_creationHigh153Free2021-08-23Zeek DCE/RPC: Remote Print Driver or Print Processor Installation Activity
Alerts on Zeek DCE-RPC RPC operations that remotely add printer drivers or print processors.
"@neu5ron (Nate Guagenti), Huntrule Team"Zeekdce_rpcMedium162Free2021-08-23Microsoft 365 Cloud App Security Alerts on Suspicious Inbox Forwarding Rules
Flags successful Microsoft Cloud App Security alerts for suspicious inbox forwarding behavior.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementLow203Free2021-08-22PowerShell Write-Hijack HackTool Creates .bat for DLL Hijack Execution (Windows)
Flags PowerShell creating .bat files consistent with PowerUp Write-Hijack DLL abuse on Windows.
Subhash Popuri (@pbssubhash), Huntrule TeamWindowsfile_eventHigh101Free2021-08-21Windows: Detect reg.exe Changing Screen Saver Registry Settings for .scr Payloads
Flags reg.exe command lines that modify HKCU desktop screensaver settings and configure a .scr screen saver payload.
frack113, Huntrule TeamWindowsprocess_creationMedium131Free2021-08-19PowerShell WMI Event Subscription Persistence via New-CimInstance
Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.
frack113, Huntrule TeamWindowsps_scriptMedium383Free2021-08-19Zeek DNS Queries Ending in Known Crypto Mining Pool Domains
Alert on Zeek DNS queries ending in mining-pool-related domains, excluding local/rejected answers.
Saw Winn Naung, Azure-Sentinel, @neu5ron, Huntrule TeamZeekdnsLow81Free2021-08-19Microsoft 365 SecurityComplianceCenter: User Restricted From Sending Email
Alerts when Microsoft 365 SecurityComplianceCenter reports a user was successfully restricted from sending email due to sending-limit policy violations.
austinsonger, Huntrule TeamM365threat_managementMedium4510Free2021-08-19Microsoft 365 Cloud App Security: Unusual Large Volume of File Deletion
Alerts when Microsoft 365 threat telemetry shows a user successfully deleting an unusually large number of files.
austinsonger, Huntrule TeamM365threat_managementMedium121Free2021-08-19