Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,127 rules
Windows: Renamed Sysinternals DebugView Process Execution
Flags Windows executions labeled as Sysinternals DebugView when the image is not the original Dbgview.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh124Free2020-05-28Windows: New Executables Named After System Processes in Non-System Paths
Alerts on creation of executables named like common system processes in unexpected Windows directories.
Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium91Free2020-05-26ComRAT Proxy HTTP Requesting index.php with h Parameter
Flags proxy HTTP requests with URIs containing /index/index.php?h=, consistent with web-based C2 behavior.
Florian Roth (Nextron Systems), Huntrule Team—proxyHigh72Free2020-05-26Confluence CVE-2019-3398 Web Exploitation via Path Traversal Upload POST Request
Alert on Confluence POST /upload.action requests with query-based path traversal filename patterns consistent with CVE-2019-3398.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical344Free2020-05-26Windows process command lines matching May 2020 Turla ComRAT command patterns
Triggers on Windows command lines matching a set of Turla-related indicators documented by ESET (May 2020).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical432Free2020-05-26Windows netsh.exe Whitelists Allowed Program from Suspicious Path in Firewall
Flags netsh.exe firewall allow rules that whitelist a program located in suspicious Windows filesystem paths.
Sander Wiebing, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh435Free2020-05-25Windows RDP Port 3389 Allowed via netsh.exe Firewall Rule Creation
Flags netsh.exe commands that add firewall rules allowing TCP port 3389 (RDP).
Sander Wiebing, Huntrule TeamWindowsprocess_creationHigh364Free2020-05-23Windows Registry: Office VBAWarning Disabled (VBAWarnings set to 1)
Alerts on Security\VBAWarnings being set to DWORD 0x00000001, enabling all Office VBA macros.
Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh92Free2020-05-22Windows Registry Set AccessVBOM DWORD=1 Disables Access Security for Access VBA
Alerts on Windows registry changes setting Security\AccessVBOM to DWORD 1, disabling VBA trust access to bypass Office warnings.
Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh375Free2020-05-22Windows: CrackMapExec PowerShell obfuscation via join/split static patterns
Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.
Thomas Patzke, Huntrule TeamWindowsprocess_creationHigh81Free2020-05-22Windows NTLM Logon to TERMSRV on Non-Domain Hosts
Alerts on Windows NTLM events tied to TERMSRV targets that may be non-domain hosts, suggesting potential RDP access.
James Pemberton, Huntrule TeamWindowsntlmMedium115Free2020-05-22Windows: Process executions matching Greenbug espionage tool indicators
Alerts on Windows process creation with command-line patterns matching PowerShell execution-policy bypass and reverse-shell related tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical3410Free2020-05-20Linux auditd: New user account creation via useradd (ADD_USER/SYSCALL)
Flags Linux auditd evidence of new local user accounts created using useradd.
Marie Euler, Pawel Mazur, Huntrule TeamLinuxauditdMedium465Free2020-05-18Linux auditd: Alert on suspicious C2-related command executions
Alerts on auditd executions of common C2-adjacent tools when labeled with the "susp_activity" key.
Marie Euler, Huntrule TeamLinuxauditdMedium173Free2020-05-18Windows Network Connections Initiated by Notepad.exe
Alerts when notepad.exe initiates an outbound network connection, excluding typical printing traffic on port 9100.
EagleEye Team, Huntrule TeamWindowsnetwork_connectionHigh196Free2020-05-14