Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,121 rules
Advanced IP Scanner Execution from Temp Folder via Windows File Events
Flags file activity targeting Advanced IP Scanner 2 under a Windows user Temp directory.
"@ROxPinTeddy, Huntrule Team"Windowsfile_eventMedium193Free2020-05-12Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
NVISO, Huntrule TeamWindowsfile_eventHigh82Free2020-05-11Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical169Free2020-05-08Azure Activity Logs: Alert on First-Time Source IP for Subscription-Level Rare Operations
Alerts when specified Azure subscription operations occur from a new, previously unseen source IP.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium142Free2020-05-07Azure Activity Logs: Granting Role Assignments from New Source IPs
Alerts on Azure role assignment permission grants when they originate from a new source IP in Activity Logs.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium359Free2020-05-07Azure Activity Logs: High Rate of VM Creations or Deployment Writes
Flags Azure activity log events showing VM creation or deployment write operations occurring at an anomalously high volume.
sawwinnnaung, Huntrule TeamAzureactivitylogsMedium153Free2020-05-07Windows Security Log: Metasploit SMB NTLM Logon (4624/4625, 4776)
Detects Metasploit-linked NTLM SMB authentication activity using Windows 4624/4625 and 4776 with 16-char workstation names.
Chakib Gzenayi (@Chak092), Hosni Mribah, Huntrule TeamWindowssecurityHigh3710Free2020-05-06Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Alerts on Windows failed logons (4625) originating from IPs outside private/local ranges.
NVISO, Huntrule TeamWindowssecurityMedium356Free2020-05-06Windows Fax Service ualapi.dll Side-Loading via fxssvc.exe
Flags fxssvc.exe loading ualapi.dll from unexpected paths, indicating potential DLL side-loading for privilege escalation.
NVISO, Huntrule TeamWindowsimage_loadHigh72Free2020-05-04Windows AppCompatFlags Store New Application Registry Entries
Alerts on new writes to the AppCompat Compatibility Assistant store registry path, indicating first-time application behavior.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setInformational3410Free2020-05-02Windows Registry Deletion of Shell Open Command COM Hijacking Key Paths
Flags registry deletions of \shell\open\command paths that may indicate removal of COM hijacking execution entries.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_deleteMedium103Free2020-05-02Windows sdclt.exe Spawned with High Integrity (Possible UAC Bypass)
Alerts on sdclt.exe launching as High integrity, indicating possible elevated execution consistent with UAC bypass attempts.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium92Free2020-05-02Windows Process Creation: .NET ETW Logging Environment Variables Set via Command Line
Flags process command lines setting COMPlus_ETWEnabled/COMPlus_ETWFlags, potentially impairing ETW logging for .NET.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationHigh336Free2020-05-02Windows sdclt.exe Child Process Creation
Alerts when sdclt.exe launches a child process, a behavior consistent with abused Windows binaries in escalation chains.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium273Free2020-05-02Windows rundll32 WebDAV Client Execution (davclnt.dll DavSetCookie)
Flags svchost.exe spawning rundll32.exe to run davclnt.dll,DavSetCookie, consistent with WebDAV client execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationMedium60Free2020-05-02