Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,132 rules
Windows Registry Set: .NET COR/CORECLR Profiling Environment Variables Enabled
Alerts on registry writes enabling .NET CLR/CORECLR profiling variables like COR_ENABLE_PROFILING and COR_PROFILER.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Jimmy Bayne (@bohops), Huntrule TeamWindowsregistry_setMedium417Free2020-09-10Windows Process Creation: MpCmdRun.EXE Used to Download Files via DownloadFile url
Alerts when MpCmdRun.exe is executed with DownloadFile and url, indicating Defender utility file download behavior.
Matthew Matchen, Huntrule TeamWindowsprocess_creationHigh181Free2020-09-04WMI scrcons.exe Loading Script and WMI DLLs via Image Load (Windows)
Alerts when scrcons.exe loads vbscript/wbem/WMI script DLLs, suggesting WMI ActiveScriptEventConsumer activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium103Free2020-09-02Windows Security 4624 Logon for scrcons.exe Indicating Remote WMI ActiveScriptEventConsumers
Flags remote network logons involving scrcons.exe that may indicate WMI ActiveScriptEventConsumers activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityMedium70Free2020-09-02Windows Process Creation Indicators for Snatch Ransomware Word Document Droppers
Alerts on Windows process command lines showing instant safe-mode shutdown/reboot and stopping SuperBackupMan service.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2020-08-26Zeek: Public RDP Connections from Non-Private IPv4/IPv6 Ranges
Alert on Zeek-observed RDP connections originating from non-excluded IP ranges, suggesting external accessibility.
Josh Brower @DefensiveDepth, Huntrule TeamZeekrdpHigh225Free2020-08-22Windows Process Creation: Mouse Lock Execution with “Misc314” Indicator
Alerts on Windows executions of Mouse Lock where Company includes “Misc314” and CommandLine contains “Mouse Lock_”.
Cian Heasley, Huntrule TeamWindowsprocess_creationMedium101Free2020-08-13Windows Defender windefend Event 1013: Malware detection history deletion
Alerts when Windows Defender deletes its malware/PUA detection history via windefend Event ID 1013.
Cian Heasley, Huntrule TeamWindowswindefendInformational298Free2020-08-13Windows Security Event 5145: SMB Write Access to Admin Share (C$)
Flags non-machine accounts writing via SMB to the C$ administrative share using Security EventID 5145.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh132Free2020-08-06Webserver logs: Webshell ReGeorg indicators in POST URI query with null Referer/User-Agent
Flags HTTP POST requests with null referer/user-agent and ReGeorg-like URI query parameters in web logs.
Cian Heasley, Huntrule TeamWebwebserverHigh161Free2020-08-04Windows Process Creation: Winnti Pipemon setup* Command-Line Parameters
Alerts on Windows processes launching Pipemon-style setup.exe command lines with specific -p or -x:n flags.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationCritical224Free2020-07-30Windows TAIDOOR RAT DLL Load via rundll32 Command Line
Detects Windows process creation command lines consistent with TAIDOOR RAT DLL loading through rundll32.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2020-07-30Windows windefend Event ID 5012: Windows Defender virus scanning disabled
Flags when Windows Defender disables virus scanning via windefend Event ID 5012.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh92Free2020-07-28Windows windefend: Windows Defender threat detection and mitigation events
Alerts on windefend events indicating Windows Defender malware detection and potential remediation activity.
Ján Trenčanský, Huntrule TeamWindowswindefendHigh123Free2020-07-28Windows windefend EventID 5001: Windows Defender real-time protection disabled
Flags windefend Event ID 5001 indicating Windows Defender real-time protection was disabled.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh122Free2020-07-28