Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,188 rules
Google Cloud DLP Re-identifies Sensitive Data via projects.content.reidentify
Detects Google Cloud DLP re-identification activity using projects.content.reidentify in audit logs.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium81Free2021-08-15AWS EFS Mount Target Modified or Deleted via CloudTrail
Detects CloudTrail-reported deletion of an AWS EFS mount target that can break dependent instances or applications.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailMedium92Free2021-08-15AWS EFS Filesystem Modified or Deleted via CloudTrail
Alert on AWS EFS file system deletion activity observed in CloudTrail via DeleteFileSystem events.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailMedium286Free2021-08-15GCP Audit: Service Account Modified via IAM Patch/Create/Update/Enable/Undelete
Flags GCP audit events indicating service account create, update, enable, undelete, or patch operations.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium1710Free2021-08-14Google Cloud: Service Account Disabled or Deleted via IAM Audit Events
Identifies GCP IAM audit events where service accounts are disabled or deleted via serviceAccounts.disable/delete.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium163Free2021-08-14GCP Audit: Storage Bucket Modified or Deleted via Storage API
Alert on GCP audit events indicating storage bucket insert, update, patch, or delete actions.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium448Free2021-08-14GCP Audit Alerts for Google Cloud Storage Bucket Enumeration via Listing APIs
Triggers on GCP audit events indicating Storage bucket listing (storage.buckets.list or listChannels).
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditLow133Free2021-08-14GCP Audit: Full Network Packet Capture via Compute PacketMirrorings API
Alerts on GCP Compute PacketMirrorings API calls that may enable full network packet capture.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium122Free2021-08-13GCP Audit: Firewall Rule Insert, Update, Patch, or Delete
Flags GCP audit events where firewall rules are inserted, updated, patched, or deleted.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium394Free2021-08-13Windows whoami.exe Execution from Suspicious Parent Processes
Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2021-08-12Windows whoami.exe Renamed Execution via Mismatched OriginalFileName
Alerts when a renamed process still reports OriginalFileName as whoami.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical80Free2021-08-12Windows SystemNightmare Exploitation Attempt via PrintNightmare Command Lines
Alerts on Windows process command lines matching SystemNightmare/PrintNightmare exploitation indicators that may enable LOCAL_SYSTEM shell access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical173Free2021-08-11Exchange ProxyLogon activity: IIS POST SetObject Reset VirtualDirectory requests
Alerts on successful POSTs to ECP DDIService SetObject resetting a VirtualDirectory with a '$' username suffix.
frack113, Huntrule Team—webserverCritical101Free2021-08-10Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Flags winword.exe process injection where the call trace matches LittleCorporal-generated Maldoc activity on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh132Free2021-08-09PowerShell ShellIntel Commandlet Abuse via ScriptBlock Logging
Flags PowerShell script blocks that reference known ShellIntel commandlets tied to exploitation activity.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsps_scriptHigh121Free2021-08-09