Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,180 rules
Windows Named Pipe Creation Matching Cobalt Strike Malleable C2 Profile Patterns
Alerts on Windows named pipe creation with PipeName patterns consistent with Cobalt Strike Malleable C2 behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdCritical214Free2021-07-30Windows WinDivert Driver Load via Image or Known IMPHASHes
Detects WinDivert-related Windows driver loads using loaded image paths or known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh133Free2021-07-30PowerShell SAM Hive Copy via Volume Shadow Copy Paths on Windows
Flags PowerShell commands that copy the SAM hive from Volume Shadow Copy locations using .NET or PowerShell copy semantics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh309Free2021-07-29Windows Process Creation: Automated Document and Directory Discovery via dir and findstr
Flags Windows commands combining recursive dir listing, FINDSTR usage, and document-type targeting in one execution.
frack113, Huntrule TeamWindowsprocess_creationMedium204Free2021-07-28PowerShell Script Block Collection of Documents via Recursive Get-ChildItem
Alerts on PowerShell file enumeration that recursively searches and includes common document extensions via Get-ChildItem.
frack113, Huntrule TeamWindowsps_scriptMedium323Free2021-07-28Windows: WinZip executed with password flag and archive parameters indicative of data staging
Flags Windows executions of WinZip/WinZip64 using a password flag and archive parameters that can support data staging.
frack113, Huntrule TeamWindowsprocess_creationMedium158Free2021-07-27Windows: clip.exe Execution to Copy Data to Clipboard
Flags execution of clip.exe on Windows, a common utility for copying data into the clipboard.
frack113, Huntrule TeamWindowsprocess_creationLow111Free2021-07-27Windows: 7-Zip password-protected archive creation for potential data exfiltration
Flags 7-Zip archive creation on Windows with a password flag and archive-action parameters.
frack113, Huntrule TeamWindowsprocess_creationMedium196Free2021-07-27Windows nltest.exe Recon via Server Query and Domain Trust Enumeration
Alerts on nltest.exe commands with server/query and domain trust enumeration arguments often used for Windows discovery.
Craig Young, oscd.community, Georg Lauenstein, Huntrule TeamWindowsprocess_creationMedium133Free2021-07-24Windows Hacktool Execution Indicators for SMB/NTLM Relay and Potato-Style Privilege Escalation
Alerts on Windows execution of common SMB/NTLM relay and “Potato” privilege escalation hacktool indicators via process creation fields.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical161Free2021-07-24Windows Process Creation: Impacket HackTool Binary Execution via Named Image Matches
Flags execution of Windows impacket compiled binaries based on distinctive tool names in the process Image.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh409Free2021-07-24Azure Activity Logs: Kubernetes Pod Deletion via Connected Clusters API
Flags Azure Activity Log events indicating Kubernetes pods were deleted for connected clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium93Free2021-07-24Azure Kubernetes Events Deleted via Activity Logs
Identifies Azure Activity Log entries where Kubernetes event records are deleted for connected clusters.
Austin Songer @austinsonger, Huntrule TeamAzureactivitylogsMedium4610Free2021-07-24AWS CloudTrail: IAMUser STS GetSessionToken Use
Alerts on CloudTrail STS GetSessionToken calls made by IAM users, indicating potential temporary credential misuse.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow111Free2021-07-24AWS CloudTrail: Suspicious STS AssumeRole sessions from Role-issued principals
Alert on CloudTrail AssumeRole events initiated from an already assumed role session.
Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow167Free2021-07-24