Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,128 rules
Windows Registry Modification via Process Creation Command Lines Indicative of Ke3chang/TidePool
Alerts on Windows process command lines that set IE hardening and related Internet Explorer registry properties consistent with Ke3chang/TidePool.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh63Free2020-06-18Linux process commands stopping firewall and security services
Flags Linux commands that stop/disable firewall/security services or set SELinux enforcement to 0.
Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule TeamLinuxprocess_creationMedium268Free2020-06-17Linux Process Sets HTTP/HTTPS Proxy Environment Variables
Flags Linux process command lines that set http_proxy and https_proxy values, indicating proxy configuration.
Ömer Günal, Huntrule TeamLinuxprocess_creationLow156Free2020-06-17Linux Syslog Alerts for Stopping Built-in Security Tools
Alerts on syslog text indicating security tools are being stopped: iptables, firewalld, cbdaemon, or falcon-sensor.
Ömer Günal, Alejandro Ortuno, oscd.community, Huntrule TeamLinuxsyslogMedium132Free2020-06-17Linux process activity: chown root and setuid/setgid chmod flags
Alerts on Linux command lines that set root ownership and enable setuid/setgid via chmod u+s or g+s.
Ömer Günal, Huntrule TeamLinuxprocess_creationLow111Free2020-06-16Windows Process Creation: Possible Path Traversal in cmd.exe Command Line
Alerts on Windows cmd.exe executions with "../.." path traversal indicators in parent/child command lines.
xknow @xknow_infosec, Tim Shelton, Huntrule TeamWindowsprocess_creationHigh425Free2020-06-11Windows Pcap Driver Installation via EID 4697 ServiceFileName
Flags Windows driver install events (Security 4697) where the service file name matches known Pcap-related driver keywords.
Cian Heasley, Huntrule TeamWindowssecurityMedium131Free2020-06-10Windows file indicators for Octopus Scanner malware artifacts
Alerts on Windows file activity for Octopus Scanner-related filenames (Cache134.dat, ExplorerSync.db) in AppData.
NVISO, Huntrule TeamWindowsfile_eventHigh181Free2020-06-09Windows Registry Markers for FlowCloud Malware Configuration and Keylogger Components
Detects registry activity referencing specific HARDWARE marker GUID keys and the Setup\PrintResponsor path on Windows.
NVISO, Huntrule TeamWindowsregistry_eventCritical63Free2020-06-09Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Alerts on Windows consent-store registry entries showing webcam/microphone access tied to Temp or public user paths.
Den Iuzvyk, Huntrule TeamWindowsregistry_eventHigh112Free2020-06-07Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Identifies Windows processes interacting with non-packaged app consent entries for microphone and webcam access.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityMedium101Free2020-06-07Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags
Alerts on Sysmon registry sets that set .NET ETWEnabled/COMPlus ETW flags to 0, impairing ETW-based telemetry.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh213Free2020-06-05Windows Registry ETW Logging Disabled for .NET via Security Event 4657
Alerts when .NET ETW logging is disabled via registry changes (ETWEnabled or COMPlus ETW settings) using Event ID 4657.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh172Free2020-06-05Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Identifies Windows PowerShell command lines commonly used by Covenant launchers, including hidden/encoded execution patterns.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh41Free2020-06-04Windows Process Masquerading: msdtc.exe and gpsvc.exe launched from Non-System Paths
Alerts on msdtc.exe or gpsvc.exe launched from paths outside Windows System32/SysWOW64.
Trent Liffick (@tliffick), Bartlomiej Czyz (@bczyz1), Huntrule TeamWindowsprocess_creationHigh1710Free2020-06-03