Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,118 rules
Windows: Suspicious Execution of CSharp Interactive Console via PowerShell
Alerts when PowerShell launches csi.exe, indicating possible interactive .NET code execution.
Michael R. (@nahamike01), Huntrule TeamWindowsprocess_creationHigh142Free2020-03-08Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe
Alerts when svchost.exe launches mmc.exe with “-Embedding”, indicating potential MMC20 COM-based lateral movement.
"@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea), Huntrule Team"Windowsprocess_creationHigh427Free2020-03-04Windows: Detect Microsoft Exchange CVE-2020-0688 exploitation via Eventlog errors
Identifies Exchange Control Panel error events containing a ViewState parameter consistent with CVE-2020-0688 exploitation attempts.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowsapplicationHigh441Free2020-02-29Microsoft Exchange Web RCE Attempts via GET Requests Containing ECP/OWA and __VIEWSTATE
Alerts on web requests to Exchange ECP/OWA that include __VIEWSTATE= in the query.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical312Free2020-02-29Webserver Request Matching for CVE-2020-0688 Exploitation Attempt
Alerts when webserver URI queries include /ecp/default.aspx with __VIEWSTATEGENERATOR and __VIEWSTATE consistent with CVE-2020-0688 probing.
NVISO, Huntrule Team—webserverHigh206Free2020-02-27Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
Flags HTTP GET URIs containing SQL injection indicator strings in webserver access logs, excluding 404 responses.
Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank), Huntrule TeamWebwebserverHigh162Free2020-02-22Windows Registry: TrustRecords key modification indicating macro-based initial access
Flags Windows registry writes to Security\Trusted Documents\TrustRecords, a signal consistent with macro-enabled initial access.
Antonlovesdnb, Trent Liffick (@tliffick), Huntrule TeamWindowsregistry_eventMedium61Free2020-02-19Windows: Office Application Loads VBE VBA DLLs via Image Load Events
Flags Office apps loading VBA-related VBE DLLs, a strong indicator of VBA macro execution.
Antonlovesdnb, Huntrule TeamWindowsimage_loadHigh132Free2020-02-19Windows Office Apps Loading .NET GAC MSIL DLLs via Image Load Events
Alerts when an Office app loads a .NET DLL from the GAC_MSIL directory.
Antonlovesdnb, Huntrule TeamWindowsimage_loadHigh70Free2020-02-19Windows: CLR DLL Loaded by Office Applications
Alerts when Excel, Word, Outlook, PowerPoint, Publisher, or OneNote loads clr.dll on Windows.
Antonlovesdnb, Huntrule TeamWindowsimage_loadMedium40Free2020-02-19Windows Office Apps Loading .NET Assembly DLLs from C:\Windows\assembly
Alerts when Office applications load DLLs from C:\Windows\assembly\ via image load events.
Antonlovesdnb, Huntrule TeamWindowsimage_loadMedium40Free2020-02-19Windows Process Memory Dump via comsvcs.dll using rundll32
Alert on rundll32 loading comsvcs.dll with arguments consistent with a full process memory dump.
Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2020-02-18Windows Process Creation: Sticky Keys Backdoor via sethc.exe Replacement
Flags forced replacement of C:\Windows\System32\sethc.exe with cmd.exe consistent with a Sticky Keys backdoor.
Sreeman, Huntrule TeamWindowsprocess_creationCritical116Free2020-02-18AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance
Detects RDS restores from snapshots that result in a publicly accessible database instance in AWS CloudTrail.
faloker, Huntrule TeamAwscloudtrailHigh461Free2020-02-12AWS CloudTrail RDS ModifyDBInstance Master User Password Change
Flags AWS RDS ModifyDBInstance events that include a master user password change.
faloker, Huntrule TeamAwscloudtrailMedium132Free2020-02-12