Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,132 rules
Windows windefend: Microsoft Defender malware and PUA scanning disabled (Event ID 5010)
Flags Windows Defender disabling malware and PUA scanning using Windefend Event ID 5010.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh123Free2020-07-28Windows Defender antimalware grace period expired (Event ID 5101)
Alerts when Windows Defender signals its antimalware grace period expired via windefend Event ID 5101.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh91Free2020-07-28Windows Service Control Manager: Windows Defender Threat Protection Disabled
Flags Service Control Manager events where the Windows Defender Threat Protection (Defender Antivirus) service is stopped.
Ján Trenčanský, frack113, Huntrule TeamWindowssystemMedium458Free2020-07-28Windows webserver-spawned recon commands probing scripting tool help (perl/python/wget)
Flags webserver child processes running perl/python/python3/wget help commands to probe available tooling on the host.
Cian Heasley, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2020-07-22Windows DLL Load Indicates Potential Azure Browser SSO OAuth Token Request Abuse
Alerts on MicrosoftAccountTokenProvider.dll loads on Windows, with process-based exclusions, as a signal for potential Azure Browser SSO token activity.
Den Iuzvyk, Huntrule TeamWindowsimage_loadLow151Free2020-07-15Windows DNS Server CVE-2020-1350 RCE Indicators via Suspicious Child Process Creation
Alerts on non-benign subprocesses spawned by Windows DNS (dns.exe), consistent with CVE-2020-1350 exploitation attempts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical172Free2020-07-15Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
Bhabesh Raj, Huntrule TeamWindowswindefendHigh103Free2020-07-14Windows Sysmon Operational Channel Reference Deleted via Security Event
Detects Security log events showing Sysmon Operational channel being disabled via channel reference deletion-like changes.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh111Free2020-07-14Empire C2 Proxy Requests with Specific User-Agent and POSTed PHP URIs
Flags proxy HTTP POSTs using an Empire-like user agent to specific admin/login PHP endpoints.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh335Free2020-07-13Windows Dllhost.exe Network Connections to Non-Local IP Addresses
Flags Dllhost.exe initiating outbound connections to non-local destination IPs, excluding local/private and specified benign IP ranges.
bartblaze, Huntrule TeamWindowsnetwork_connectionMedium50Free2020-07-13Windows Process Creation: regsvr32 Invoked to Load .ocx from AppData Roaming
Flags regsvr32 /s /i loading an .ocx from AppData\Roaming on Windows, a stealthy code-loading technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical91Free2020-07-10Citrix ADC/ADS Exploitation Attempts Targeting RAPI and PCIDSS Paths (CVE-2020-8193/8195)
Flags Citrix ADC/NetScaler HTTP requests whose URI queries match exploitation-related patterns for CVE-2020-8193 and CVE-2020-8195.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical123Free2020-07-10Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2020-07-09Windows Registry Run Key Modification for ntkd Persistence
Flags Windows registry activity hitting the Run key path segment "\Run\ntkd" used for automatic startup persistence.
Aidan Bracher, Huntrule TeamWindowsregistry_eventCritical121Free2020-07-07Microsoft 365 Impossible Travel Sign-ins Reported as Successful
Alerts on successful Microsoft 365 “Impossible travel activity” events in SecurityComplianceCenter telemetry.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium224Free2020-07-06