Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,132 rules
Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Alerts when Windows process command lines include Hydra -u/-p parameters with USER/PASS placeholders.
Vasiliy Burov, Huntrule TeamWindowsprocess_creationHigh121Free2020-10-05Windows findstr.exe Subfolder and Case-Insensitive Search Flags
Alerts on findstr.exe executions that include both -s (subfolders) and -i (case-insensitive) flags.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow132Free2020-10-05Windows: SyncAppvPublishingServer.exe execution via PowerShell script block content
Flags PowerShell script blocks that reference SyncAppvPublishingServer.exe, indicating possible execution via a PowerShell-restricted workflow.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_scriptMedium131Free2020-10-05Windows SyncAppvPublishingServer Execution Triggering PowerShell Module Context
Alerts when SyncAppvPublishingServer.exe appears in PowerShell module ContextInfo on Windows.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_moduleMedium455Free2020-10-05Windows Security: Suspicious Remote Logon Using Explicit Credentials via Command-Line Tools
Flags EventID 4648 remote logons initiated by cmd/PowerShell/winrs/wmic/net/reg-style processes using explicit credentials.
oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton, Huntrule TeamWindowssecurityMedium61Free2020-10-05Linux: Process executing update-ca-certificates or update-ca-trust
Detects Linux executions of update-ca-certificates or update-ca-trust that install new trusted root certificates.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationLow172Free2020-10-05Windows Process Creation: WSL (wsl.exe) Used for Arbitrary Command Execution
Alerts when wsl.exe is launched with execution-focused options that may enable arbitrary Linux/Windows command execution.
oscd.community, Zach Stanford @svch0st, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2020-10-05Windows Process Proxying: explorer.exe Spawned from cmd.exe or PowerShell
Flags cmd.exe/powershell.exe launching explorer.exe, indicating possible proxy-based execution on Windows.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Huntrule TeamWindowsprocess_creationLow100Free2020-10-05Windows: Manual persistence attempt using schtasks to run Microsoft Compatibility Appraiser
Alerts when schtasks runs "Microsoft Compatibility Appraiser" via Application Experience, consistent with persistence abuse.
Sreeman, Huntrule TeamWindowsprocess_creationMedium116Free2020-09-29Windows service configuration tampering via sc/reg with payload execution paths
Looks for sc/reg command-line activity that updates Windows service ImagePath or FailureCommand to run attacker-controlled payloads.
Sreeman, Huntrule TeamWindowsprocess_creationMedium217Free2020-09-29Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)
Flags HKCU DelegateExecute registry changes for COM hijack style persistence under the Folder shell open command.
Omkar Gudhate, Huntrule TeamWindowsregistry_setHigh101Free2020-09-27Windows VirtualBox Driver Registration or VM Startup via Process Command Line
Alerts on Windows processes whose command lines reference VirtualBox driver registration or VM start/control actions.
Janantha Marasinghe, Huntrule TeamWindowsprocess_creationLow186Free2020-09-26Detect Wannacry killswitch DNS queries to hardcoded domains
Flags DNS lookups for known WannaCry killswitch domain strings and variants.
Mike Wade, Huntrule TeamNetworkdnsHigh121Free2020-09-16Windows NetLogon Secure Channel Connection Allowed for Vulnerable Client
Alerts on Windows NetLogon ETW events indicating an allowed secure channel connection (Event ID 5829).
NVISO, Huntrule TeamWindowssystemHigh92Free2020-09-15Windows Defender Windefend AMSI Detection (Event ID 1116)
Flags Windows Defender AMSI detections via windefend Event ID 1116 with SourceName set to AMSI.
Bhabesh Raj, Huntrule TeamWindowswindefendHigh60Free2020-09-14