Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,184 rules
Azure Activity Logs: Kubernetes ClusterRole/Role Write, Delete, Bind, or Escalate Changes
Alerts on Azure Kubernetes RBAC Role/ClusterRole writes, deletions, bind, or escalation actions in activity logs.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium254Free2021-08-07Azure Activity Logs: Kubernetes Network Policy Write/Delete Changes
Alerts on Azure Activity Log events that modify or remove Kubernetes network policies for connected clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium92Free2021-08-07Azure Activity Logs: Azure Kubernetes Connected Cluster Created or Deleted
Alerts on Azure Activity Log operations that write or delete Kubernetes Connected Clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsLow153Free2021-08-07Azure Activity Logs: Container Registry Created or Deleted
Flags Azure Activity Log events where an Azure Container Registry is created (write) or deleted.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsLow342Free2021-08-07Detects ProxyShell-Style Exchange Probing via /autodiscover.json and PowerShell URIs (HTTP 401)
Flags Exchange web requests with ProxyShell-like /autodiscover.json query patterns and PowerShell/EWS-related parameters, often returning HTTP 401.
Florian Roth (Nextron Systems), Rich Warren, Huntrule Team—webserverHigh218Free2021-08-07Windows AnyDesk Silent Installation via Command-Line Flags
Identifies AnyDesk being silently installed on Windows using --install, --start-with-win, and --silent command-line flags.
Ján Trenčanský, Huntrule TeamWindowsprocess_creationHigh163Free2021-08-06Windows esentutl Usage with /p Flag for Credential Access
Flags Windows executions of esentutl when used with the /p parameter to access credentials-related files.
sam0x90, Huntrule TeamWindowsprocess_creationMedium92Free2021-08-06Windows Registry: Tamper Protection Disabled in Microsoft Defender Features
Flags registry changes that set Microsoft Defender Tamper Protection to disabled (DWORD 0x0), excluding expected MsMpEng update activity.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium3110Free2021-08-04Windows Registry: Disabling Windows Defender PUA Protection via PUAProtection DWORD
Flags registry changes that set Windows Defender PUAProtection DWORD to 0x00000000 to disable PUA protection.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setHigh186Free2021-08-04Windows Registry: Disable Windows Defender Exploit Guard Network Protection via Policy Override
Alerts on registry policy changes that override Exploit Guard Network Protection settings for Windows Defender.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium101Free2021-08-04Windows process access matching Cobalt Strike BOF injection call trace
Flags suspicious Windows process access consistent with CobaltStrike BOF injection using ntdll/KERNELBASE call traces and high GrantedAccess.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh133Free2021-08-04PowerShell timestomping via file timestamp property and setter usage (Windows)
Identifies PowerShell timestomping attempts by matching script text that sets file creation, access, and write timestamps.
frack113, Huntrule TeamWindowsps_scriptMedium182Free2021-08-03PowerShell Virtualization Environment Discovery via WMI in ScriptBlockLogging (Windows)
Identifies PowerShell WMI queries for Win32 computer system and ACPI thermal data used to check virtualization environments.
frack113, Duc.Le-GTSC, Huntrule TeamWindowsps_scriptMedium324Free2021-08-03Windows Process Creation: ADCSPwn Command-Line Parameters Indicating ADCS Abuse
Identifies Windows processes with command-line arguments consistent with ADCSPwn targeting ADCS and a specified port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh429Free2021-07-31Windows Process Creation: Recon Data Export via Command Prompt Redirection
Alerts when recon-related Windows utilities are launched with command-line output redirected to temp locations.
frack113, Huntrule TeamWindowsprocess_creationMedium93Free2021-07-30