Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,112 rules
Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Flags Windows Event ID 6416 entries where a DiskDrive/USB Mass Storage Device is detected as connected.
Keith Wright, Huntrule TeamWindowssecurityLow96Free2019-11-20Windows CVE-2019-1388 UAC Consent to Internet Explorer Execution as LOCAL_SYSTEM
Flags UAC consent.exe launching iexplore.exe running as SYSTEM, consistent with CVE-2019-1388 exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical197Free2019-11-20Windows ProcDump Execution via Renamed Binary
Flags renamed ProcDump usage on Windows by matching procdump indicators and dump flags while excluding known executable names.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2019-11-18Webserver CVE-2019-11510 Exploitation Attempt via Guacamole URI
Alerts on web requests with a Guacamole-related URI query pattern associated with a Pulse Secure CVE-2019-11510 exploitation attempt.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical149Free2019-11-18Windows Security: Anonymous Logon (4624 LogonType 3) with Loopback IPs
Alerts on Windows 4624 LogonType 3 with ANONYMOUS LOGON and loopback IPs, matching RottenPotato-like patterns.
"@SBousseaden, Florian Roth, Huntrule Team"WindowssecurityHigh111Free2019-11-15Windows Process Creation: Suspicious SetupComplete.cmd execution for CVE-2019-1378 exploitation
Alerts on cmd.exe parent command lines executing SetupComplete.cmd or PartnerSetupComplete.cmd from Windows Setup script paths.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh187Free2019-11-15Windows msiexec.exe Execution from Uncommon Directory
Alerts when msiexec.exe starts from a non-standard path, which may indicate masquerading.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3410Free2019-11-14Windows Image Load: System.Management.Automation DLL Loaded by Non-PowerShell Process
Alerts when a non-PowerShell executable loads System.Management.Automation.dll on Windows, indicating possible PowerShell execution in another process.
Tom Kern, oscd.community, Natalia Shornikova, Tim Shelton, Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium71Free2019-11-14Suspicious APT User-Agent Strings in Proxy Logs
Alerts when proxy requests contain known APT-style user agent strings indicating likely malicious client behavior.
Florian Roth (Nextron Systems), Markus Neis, Huntrule TeamWebproxyHigh152Free2019-11-12Proxy User-Agent Matching APT40 Dropbox Tool on api.dropbox.com
Alerts on proxy requests using a fixed Chrome 36 user-agent to api.dropbox.com.
Thomas Patzke, Huntrule Team—proxyHigh132Free2019-11-12Windows: Command-line contains long ab-prefixed string seen in TropicTrooper activity (Nov 2018)
Detects Windows processes whose command line contains a known TropicTrooper campaign indicator string.
"@41thexplorer, Microsoft Defender ATP, Huntrule Team"Windowsprocess_creationHigh168Free2019-11-12Windows Process Creation: Detect Obfuscated PowerShell IEX Invocation from Invoke-Obfuscation
Detects PowerShell commands showing obfuscation markers consistent with Invoke-Obfuscation-powered IEX invocation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsprocess_creationHigh143Free2019-11-08PowerShell: Obfuscated IEX Invocation via Invoke-Obfuscation String/Variable Patterns
Alerts on obfuscated PowerShell IEX invocation strings built from Invoke-Obfuscation style concatenation patterns in ScriptBlockText.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsps_scriptHigh124Free2019-11-08PowerShell Module Obfuscated IEX Invocation via Invoke-Obfuscation Payload Patterns
Alerts when PowerShell module payloads contain patterns consistent with obfuscated IEX generation via Invoke-Obfuscation.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowsps_moduleHigh71Free2019-11-08Windows System Service Creation of Obfuscated PowerShell IEX (Invoke-Obfuscation)
Flags Windows service creations whose ImagePath contains obfuscated PowerShell IEX invocation strings.
Daniel Bohannon (@Mandiant/@FireEye), oscd.community, Huntrule TeamWindowssystemHigh3010Free2019-11-08