Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,176 rules
Windows Registry Changes Enabling DNS-over-HTTPS via Edge, Chrome, or Firefox Policies
Alerts on registry policy updates that enable DNS-over-HTTPS for Edge, Chrome, or Firefox on Windows.
Austin Songer, Huntrule TeamWindowsregistry_setMedium102Free2021-07-22AWS Route 53 Domain Transfer to Another Account via TransferDomainToAnotherAwsAccount
Alerts on Route 53 domain transfer requests in CloudTrail when a domain is moved to another AWS account.
Elastic, Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow161Free2021-07-22AWS Route 53 Domain Transfer Lock Disabled via CloudTrail
Alerts when Route 53 domain transfer protection is removed through DisableDomainTransferLock events in CloudTrail.
Elastic, Austin Songer @austinsonger, Huntrule TeamAwscloudtrailLow3910Free2021-07-22Windows Process Creation: Netcat (ncat/cat) Suspicious Execution
Alerts on Windows process launches of Netcat-like binaries with typical listener/proxy or remote execution command-line flags.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh386Free2021-07-21Windows PowerShell Script Block Local Email Collection via Outlook COM Automation
Flags PowerShell script block text referencing Outlook COM automation used to collect locally stored email.
frack113, Huntrule TeamWindowsps_scriptMedium359Free2021-07-21PowerShell command line containing powercat invocation on Windows
Alerts when classic PowerShell starts with Powercat-related command-line strings ('powercat ' or 'powercat.ps1').
frack113, Huntrule TeamWindowsps_classic_startMedium2710Free2021-07-21Windows Private Key File Recon via cmd.exe, PowerShell, or findstr.exe
Flags Windows command-line searches for key/certificate file extensions using cmd.exe, PowerShell, or findstr.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2021-07-20PowerShell Compress-Archive Creates Archive in Temp or System Temp Paths
Flags PowerShell Compress-Archive usage writing archives to %TEMP%, AppData Local Temp, or Windows Temp.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium141Free2021-07-20PowerShell: Compress-Archive to TEMP/AppData/Windows Temp for Staging
Flags PowerShell scripts compressing data with Compress-Archive into $env:TEMP or Temp folders.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_scriptMedium143Free2021-07-20Windows PowerShell module usage: Compress-Archive to store archives in Temp locations
Alerts on PowerShell Compress-Archive output written to common temp staging directories.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleMedium81Free2021-07-20PowerShell Classic Compress-Archive staging in TEMP or Temp directories
Alerts on PowerShell Compress-Archive output targeting common Temp directories for data staging.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowspowershell-classicMedium4810Free2021-07-20Windows mshta.exe Process Creation Triggered by Suspicious Command Lines
Alert on mshta.exe launches from suspicious parents and script-like command lines/paths.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2021-07-17Windows Process Execution of SyncAppvPublishingServer.vbs with Inline PowerShell Commands
Flags Windows executions of SyncAppvPublishingServer.vbs with a semicolon-augmented command line consistent with embedded PowerShell.
frack113, Huntrule TeamWindowsprocess_creationMedium131Free2021-07-16PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh275Free2021-07-16Windows Registry Modification Indicative of CVE-2021-31979 and CVE-2021-33771 Exploitation
Flags registry changes to targeted COM InprocServer32 CLSID paths tied to CVE-2021-31979/33771 exploitation behavior on Windows.
Sittikorn S, frack113, Huntrule TeamWindowsregistry_setCritical318Free2021-07-16