Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,161 rules
Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh112Free2021-04-23PowerShell ScriptBlock Certificate Export via Export-PfxCertificate or Export-Certificate
Detects PowerShell script blocks invoking certificate export cmdlets, which may be abused to steal sensitive certificate material.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptMedium81Free2021-04-23Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Flags HybridConnectionManager-initiated DNS queries to servicebus.windows.net on Windows.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsdns_queryHigh116Free2021-04-12Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Flags Windows Hybrid Connection Manager-related events mentioning sb:// and servicebus.windows.net.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsmicrosoft-servicebus-clientHigh82Free2021-04-12Windows Security Event 4697: HybridConnectionManager Service Installation
Alerts on HybridConnectionManager service installation on Windows via Security Event ID 4697.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh3310Free2021-04-12Windows Registry: Outlook Macro Security Level Set to Enable All Macros
Detects Outlook macro warning bypass by setting the Outlook security level registry value to enable all macros.
"@ScoubiMtl, Huntrule Team"Windowsregistry_setHigh101Free2021-04-05Windows Persistence: Outlook LoadMacroProviderOnBoot Registry Setting Modification
Alerts on enabling the Outlook LoadMacroProviderOnBoot registry setting, which can allow automatic VBA module loading at startup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh338Free2021-04-05Windows: New Outlook VBAProject OTM Macro File Created
Flags Windows file creation of Outlook VBAProject.OTM when initiated by outlook.exe.
"@ScoubiMtl, Huntrule Team"Windowsfile_eventMedium102Free2021-04-05Windows Exchange Management: Set-OabVirtualDirectory ExternalUrl to script content
Detects Exchange Management changes to OAB ExternalUrl containing script indicators and Page_Load.
Jose Rodriguez @Cyb3rPandaH, Huntrule TeamWindowsmsexchange-managementHigh296Free2021-03-15Windows schtasks.exe Creating One-Time Scheduled Tasks Using Temp Folder
Alerts on schtasks.exe commands that create one-time scheduled tasks referencing a Temp directory.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh439Free2021-03-11Windows: Suspicious Service Binary Executed from Public/System Directories
Alerts on service-hosted processes executing from user/public or system-writable directories on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2021-03-09Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical172Free2021-03-09Windows Registry: VBScript/HTMLApplication Payload Stored Under Run Keys
Flags registry persistence where script payload indicators like vbscript: and RunHTMLApplication appear in set registry values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh235Free2021-03-05Windows Process Creation: rundll32.exe Command Line Invoking .sys Files
Flags Windows rundll32.exe executions whose command line references .sys file patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2021-03-05