Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,116 rules
AWS GuardDuty CreateIPSet Trusted IP Set Changes (CloudTrail)
Alerts on CloudTrail GuardDuty CreateIPSet events that add or update trusted IP address sets.
faloker, Huntrule TeamAwscloudtrailHigh102Free2020-02-11Windows DNS analytic events for GALLIUM-related ddns QNAMEs (EventID 257)
Alert on Windows DNS analytical EventID 257 queries for GALLIUM-linked suspicious QNAMEs.
Tim Burrell, Huntrule TeamWindowsdns-server-analyticHigh306Free2020-02-07Windows Process Creation alerts on GALLIUM-associated hash IOCs
Flags Windows process executions where the file hash matches hardcoded GALLIUM-associated SHA256/SHA1 IOCs.
Tim Burrell, Huntrule TeamWindowsprocess_creationHigh1610Free2020-02-07Windows: Flag SettingSyncHost.exe used to execute RoamDiag.cmd from cmd.exe
Flags non-System32/SysWOW64 processes spawned by SettingSyncHost.exe running RoamDiag.cmd via cmd.exe /c -outputpath.
Anton Kutepov, oscd.community, Huntrule TeamWindowsprocess_creationHigh356Free2020-02-05Windows: Dumpert Process Dumper Execution via Dumpert.dll or Known MD5
Detects Dumpert execution on Windows via known hash and command line reference to Dumpert.dll for lsass memory dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical185Free2020-02-04Windows File Creation of Dumpert Default Dump (dumpert.dmp)
Alerts on creation of Dumpert’s default "dumpert.dmp" dump file on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical213Free2020-02-04Windows process activity matching Winnti malware traits from ProgramData\DRM paths
Detects suspicious Winnti-like execution where ProgramData\DRM processes spawn specific child binaries with known parent path patterns.
Florian Roth (Nextron Systems), Markus Neis, Huntrule TeamWindowsprocess_creationCritical367Free2020-02-01PowerShell CommandLine Uses FromBase64String to Decode Base64 Content (Windows)
Detects PowerShell process creation where the command line includes ::FromBase64String(, indicating Base64 decoding.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh73Free2020-01-29Windows renamed dctask64.exe execution via known IMPHASH values
Flags Windows process creations where a renamed dctask64.exe execution matches known IMPHASH values.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh41Free2020-01-28Windows Process Creation: Detect dctask64.exe with Endpoint Central Execution/Injection Flags
Alerts on Windows execution of ManageEngine Endpoint Central dctask64.exe with specific hash and suspicious command-line indicators.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2020-01-28Windows MSTSC Shadowing CommandLine Using shadow:
Flags Windows processes launching MSTSC with noconsentprompt and shadow: parameters consistent with RDP session shadowing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2020-01-24AWS CloudTrail: Root User Credential Usage (UserIdentity.type=Root)
Alerts on CloudTrail activity performed by AWS account root credentials.
vitaliy0x1, Huntrule TeamAwscloudtrailMedium123Free2020-01-21AWS CloudTrail: AWS Config Delivery Channel/Recorder Disabled
Identifies CloudTrail actions that delete AWS Config delivery channels or stop the configuration recorder.
vitaliy0x1, Huntrule TeamAwscloudtrailHigh112Free2020-01-21AWS CloudTrail Trail Stop/Update/Delete Activity
Detects CloudTrail stop, update, or delete actions that can impair logging and audit visibility.
vitaliy0x1, Huntrule TeamAwscloudtrailMedium2410Free2020-01-21Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Alerts on Windows Audit-CVE EventID 1 entries from Microsoft-Windows-Audit-CVE provider indicating CveEventWrite activity.
Florian Roth (Nextron Systems), Zach Mathis, Huntrule TeamWindowsapplicationCritical412Free2020-01-15