Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,167 rules
Windows Process Creation: SDelete Used for File Overwrite
Alerts when sdelete.exe runs in a way consistent with file overwrite to impede forensic recovery.
frack113, Huntrule TeamWindowsprocess_creationHigh296Free2021-06-03Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
frack113, Huntrule TeamWindowsps_classic_startHigh369Free2021-06-03Windows Rundll32 Loads DLL Export StartNodeRelay (F-Secure C3)
Flags rundll32.exe launching a DLL that references the StartNodeRelay export in its command line.
Alfie Champion (ajpc500), Huntrule TeamWindowsprocess_creationCritical435Free2021-06-02Windows Rundll32 Used to Start Cobalt Strike DLL Load via StartW
Alerts on rundll32.exe command lines that include a .dll and StartW function, consistent with Cobalt Strike DLL loading.
Wojciech Lesicki, Huntrule TeamWindowsprocess_creationHigh143Free2021-06-01Nginx service core dump after worker crash (signal 6)
Flags Nginx worker crashes that end with signal 6 core dumps, which may indicate serious issues or exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWebnginxHigh192Free2021-05-31Windows Security Event 4663: ISO CD-ROM device mount activity
Alerts on Windows file-access events consistent with ISO mounting by activity under \\Device\\CdRom.
Syed Hasan (@syedhasan009), Huntrule TeamWindowssecurityMedium131Free2021-05-29Windows rundll32.exe Started Without Command-Line Parameters
Alerts on Windows process launches of rundll32.exe with no parameters, excluding likely benign parent paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-05-27Windows: regedit.exe launched with TrustedInstaller or Process Hacker parent
Alerts when regedit.exe is launched by TrustedInstaller.exe or ProcessHacker.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh394Free2021-05-27Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Flags Windows service installs for ProcessHacker-prefixed services running as LocalSystem.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh231Free2021-05-27Windows: Rclone Configuration File Creation via rclone config path
Alerts on creation of rclone config files under a Windows user profile path.
Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsfile_eventMedium183Free2021-05-26Windows DNS Queries for userstorage.mega.co.nz Subdomain
Alerts on DNS queries referencing MEGA userstorage subdomains from Windows hosts.
Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsdns_queryMedium122Free2021-05-26Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssystemCritical245Free2021-05-26Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssecurityHigh103Free2021-05-26Windows Named Pipe Creation Matching Cobalt Strike Default Pipe Prefixes
Flags Windows named pipe creation where PipeName matches known Cobalt Strike default pipe prefixes.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowspipe_createdCritical131Free2021-05-25Linux PAM TTY Audit Enabling via /etc/pam.d Modification
Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.
Pawel Mazur, Huntrule TeamLinuxauditdHigh152Free2021-05-24