Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,188 rules
Microsoft Exchange: Mailbox export to UNC path or .aspx filename with possible role assignment
Flags Exchange mailbox export commands targeting UNC paths with .aspx or granting the Mailbox Import Export role.
Florian Roth (Nextron Systems), Rich Warren, Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical284Free2021-08-09Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation
Flags Exchange management command lines invoking Set-OabVirtualDirectory with suspicious external URL/script injection patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical4010Free2021-08-09GCP Kubernetes Engine audit logs: Secrets created, updated, patched, or deleted
Alerts on GCP Kubernetes audit events showing Secrets being updated, patched, or deleted via Kubernetes API calls.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium237Free2021-08-09GCP Kubernetes RBAC RoleBinding Create/Patch/Update/Delete Audit Events
Flags GCP audit events where Kubernetes RBAC RoleBindings/ClusterRoleBindings are created, modified, or removed.
Austin Songer @austinsonger, Huntrule TeamGcpgcp.auditMedium111Free2021-08-09AWS CloudTrail UpdateLoginProfile: Password/Authentication Profile Modified for Another User
Flags AWS IAM UpdateLoginProfile events where an account updates another user’s login profile password.
toffeebr33k, Huntrule TeamAwscloudtrailHigh3310Free2021-08-09Windows Process Creation: Detects Volume Shadow Copy Listing via vssadmin
Alerts on Windows command lines that list VSS shadow copies and write results to log.txt.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2021-08-09Successful ProxyShell-like Exchange exploitation via autodiscover.json and PowerShell/MAPI paths
Flags Exchange-targeted web requests with /autodiscover.json plus exploit URI fragments returning 200/301.
Florian Roth (Nextron Systems), Rich Warren, Huntrule Team—webserverCritical123Free2021-08-09Azure Activity Logs: VPN Connection Modified or Deleted
Alerts on Azure VPN connection updates or removals recorded in Activity Logs.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium168Free2021-08-08Azure Activity Logs: Virtual Network Modified or Deleted
Alerts on Azure Activity Log operations that modify (WRITE) or delete (DELETE) Virtual Network resources.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium92Free2021-08-08Azure Virtual Network Device Modified or Deleted via Activity Logs
Alerts on Azure Activity Log operations that write or delete virtual network devices such as NICs, virtual appliances, hubs, and routers.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium93Free2021-08-08Azure Activity Log: Network Security Group Config Modified or Deleted
Alerts on Azure Activity Log operations indicating NSG or NSG security rule changes (write/delete) that can weaken network security.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium142Free2021-08-08Azure Activity Logs: Point-to-site VPN Gateway Modified or Deleted
Flags Azure Point-to-site VPN gateway modifications or deletions from Activity Log operation events.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium414Free2021-08-08Azure Firewall Rule Configuration Modified or Deleted via Activity Logs
Flags Azure Activity Log write/delete operations that modify or delete firewall rule groups or rule collection groups.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium121Free2021-08-08Azure Firewall Rule Collection Modified or Deleted via Activity Logs
Alerts on Azure Firewall rule collection write or delete operations for Application, NAT, or Network components.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium82Free2021-08-08Azure Firewall Created, Modified, or Deleted via Activity Log
Alerts on Azure Firewall write or delete events in Azure Activity Logs, signaling potential defense impairment.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium113Free2021-08-08