Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,120 rules
PowerShell Local User Creation via New-LocalUser
Flags PowerShell usage of New-LocalUser, indicating creation of a Windows local user.
"@ROxPinTeddy, Huntrule Team"Windowsps_scriptMedium40Free2020-04-11Zeek SMB: Network Share File Transfers of Credential-Related Filenames
Flags Zeek-observed SMB share file transfers involving credential/dump-related filenames.
"@neu5ron, Teymur Kheirkhabarov, oscd.community, Huntrule Team"Zeeksmb_filesMedium178Free2020-04-02Zeek SMB File Access to Sensitive Email/Database/Backup Extensions
Alerts on Zeek-observed SMB file accesses to filenames ending with high-value sensitive extensions.
Samir Bousseaden, @neu5ron, Huntrule TeamZeeksmb_filesMedium396Free2020-04-02Windows: Alert on Suspicious HH.EXE Process Execution
Alerts on HH.exe execution where the command line references temp, downloads, Outlook, or other writable directories.
Maxim Pavlunin, Huntrule TeamWindowsprocess_creationHigh71Free2020-04-01Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2020-04-01Windows Security Event 4662: Non-Machine Account Reads Domain User Object Properties
Alert on AD user property read attempts in Windows Event 4662 from non-machine accounts.
Maxime Thiebaut (@0xThiebaut), Huntrule TeamWindowssecurityMedium93Free2020-03-30Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
NVISO, Huntrule TeamWindowsps_scriptHigh132Free2020-03-26Windows Process Creation: Java exploitation chain targeting Zoho ManageEngine Desktop Central (CVE-2020-10189)
Alerts on cmd/Pwsh/BITSAdmin and other command utilities launched by the Desktop Central Java runtime.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2020-03-25Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
Teymur Kheirkhabarov, Harish Segar, Huntrule TeamWindowsprocess_creationHigh268Free2020-03-20PowerShell Downgrade Attempts via -Version 2 on Windows Process Creation
Alerts on PowerShell executions specifying a -Version 2 argument, consistent with potential downgrade attempts.
Harish Segar (rule), Huntrule TeamWindowsprocess_creationMedium281Free2020-03-20Windows Desktop.ini Accessed by Uncommon Process
Alerts when unexpected processes create or access Desktop.ini, which can be abused to change how Explorer displays folder contents.
Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO), Huntrule TeamWindowsfile_eventMedium92Free2020-03-19Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Alerts on Zeek SMB file events suggesting Impacket SecretDump-style staging in ADMIN$ under SYSTEM32 with .tmp files.
Samir Bousseaden, @neu5ron, Huntrule TeamZeeksmb_filesHigh293Free2020-03-19Zeek DCE-RPC spoolss and IRemoteWinspool Calls Indicating Windows Print-Related Persistence
Alerts on specific Zeek DCE-RPC endpoint/operation combinations linked to Windows persistence techniques.
"@neu5ron, SOC Prime, Huntrule Team"Zeekdce_rpcMedium3110Free2020-03-19Zeek DCE-RPC Execution Indicators: JobAdd, Task Scheduler RPC, WMI ExecMethod, and Service Creation/Start
Detects Zeek DCE-RPC calls that match execution-related JobAdd, Task Scheduler, WMI, or service create/start operations.
"@neu5ron, SOC Prime, Huntrule Team"Zeekdce_rpcMedium123Free2020-03-19Windows Process Execution of .SettingContent-ms Command Line
Flags Windows processes whose command lines reference .SettingContent-ms, a potential trigger for setting-based execution.
Sreeman, Huntrule TeamWindowsprocess_creationMedium317Free2020-03-13