Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,120 rules
Windows PowerShell Get-Clipboard Command Execution
Flags PowerShell activity that includes the Get-Clipboard command, which may be used to collect clipboard contents.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleMedium289Free2020-05-02PowerShell Decompress via Expand-Archive
Alerts on PowerShell usage of Expand-Archive, a common decompression step attackers may use to unpack files.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsps_moduleInformational93Free2020-05-02Windows Startup Directory File Writes for Persistence
Alerts on file writes into the Windows Startup folder that may indicate user-level persistence.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventMedium2410Free2020-05-02Windows File Deletion Using Sysinternals SDelete (SDelete rename suffixes)
Flags Windows file deletions targeting filenames ending in .AAA or .ZZZ consistent with SDelete-style artifact removal.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_deleteMedium94Free2020-05-02Zeek: Detect WebDAV User-Agent with HTTP PUT to local or RFC1918 addresses
Flags Zeek HTTP PUT requests with a WebDAV User-Agent that target non-excluded network addresses.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamZeekhttpLow153Free2020-05-02Windows Image Load of System.Drawing.ni.dll
Alerts when a Windows process loads System.Drawing.ni.dll, which may indicate visual data collection activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadLow50Free2020-05-02Windows PFX File Creation From File Events
Flags Windows file events where a .pfx (certificate + private key) is created, excluding a few common benign locations.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventLow50Free2020-05-02Windows findstr Launches .lnk via Command Line
Flags find.exe or findstr.exe processes whose command lines end with a .lnk file.
Trent Liffick, Huntrule TeamWindowsprocess_creationMedium71Free2020-05-01WebDAV Delivery of Executable Files over HTTP (Zeek)
Flags Zeek HTTP events where WebDAV traffic serves an .exe with MIME type 'dosexec'.
SOC Prime, Adam Swan, Huntrule TeamZeekhttpMedium72Free2020-05-01Windows winget Installs Applications Using Local Manifest File
Flags winget.exe install commands that specify a local manifest file via -m/--manifest.
Sreeman, Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium101Free2020-04-21Windows Process Command Lines Writing Malicious Files to C:\Windows\Fonts
Flags Windows command lines that create or copy files into C:\Windows\Fonts\ using suspicious file extensions.
Sreeman, Huntrule TeamWindowsprocess_creationMedium356Free2020-04-21Windows Netsh.exe WLAN profile key clearing used for WiFi credential harvesting
Detects netsh.exe command-line activity targeting WLAN and clearing keys, indicative of potential WiFi credential harvesting on Windows.
Andreas Hunkeler (@Karneades), oscd.community, Huntrule TeamWindowsprocess_creationMedium92Free2020-04-20Windows: Process Execution of Suspicious hxtsr.exe (Outside WindowsApps)
Alerts when hxtsr.exe runs from a non-expected WindowsApps Microsoft.WindowsCommunicationsApps location.
Sreeman, Huntrule TeamWindowsprocess_creationMedium246Free2020-04-17AWS CloudTrail EC2 CreateInstanceExportTask Failure
Flags failed EC2 VM export task creation events in AWS CloudTrail to surface potential instance data extraction attempts.
Diogo Braz, Huntrule TeamAwscloudtrailLow101Free2020-04-16Proxy Downloads Containing /pwndrop/ (PwnDrp Web Server)
Alerts on proxy requests to URIs containing '/pwndrop/', consistent with PwnDrp-style web delivery.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical122Free2020-04-15