Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,100 rules
Windows Security Event DCShadow Indicators via New Service Principal Name GC/
Flags Windows Security events where a servicePrincipalName starting with "GC/" is created, consistent with DCShadow-style SPN registration.
Ilyas Ochkov, oscd.community, Chakib Gzenayi (@Chak092), Hosni Mribah, Huntrule TeamWindowssecurityMedium72Free2019-10-25Windows Security: New or Renamed User Account Name Containing '$'
Alerts on Windows user create/rename events when the account name contains '$', excluding the HomeGroupUser$ exception.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowssecurityMedium113Free2019-10-25Linux auditd alerts on syslog daemon configuration file changes
Alerts when syslog daemon configuration files are changed on a Linux host via auditd PATH events.
Mikhail Larin, oscd.community, Huntrule TeamLinuxauditdHigh102Free2019-10-25Linux auditd: Monitor changes to /etc/audit, /etc/libaudit.conf, and /etc/audisp files
Flags modifications to Linux auditd configuration files that can weaken host auditing.
Mikhail Larin, oscd.community, Huntrule TeamLinuxauditdHigh111Free2019-10-25Windows Process Creation: WSReset.exe Used with Non-CONHOST Child Process
Alerts when wsreset.exe spawns a process other than conhost.exe, a potential UAC-bypass precursor.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Florian Roth, Huntrule TeamWindowsprocess_creationHigh315Free2019-10-24Windows: Detect Fodhelper.exe spawned processes indicative of UAC bypass
Flags process creation where the parent is Fodhelper.exe, a common UAC bypass execution pattern on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamWindowsprocess_creationHigh60Free2019-10-24Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Alerts when cmstp.exe is launched with INF installation and silent/auto options indicating a UAC-bypass style behavior.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh192Free2019-10-24Windows Process Creation: tapinstall.exe Execution
Alerts on tapinstall.exe being executed on Windows, excluding known VPN driver installer paths.
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowsprocess_creationMedium427Free2019-10-24Windows Process Creation: Web Request Cmdlets and CLI Tools Usage
Alerts on Windows CommandLine usage of web request cmdlets/tools like Invoke-WebRequest, Invoke-RestMethod, curl, wget, and BITS transfer.
James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium73Free2019-10-24Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2019-10-24Windows Process Creation: SoundRecorder audio capture using /FILE
Flags SoundRecorder.exe launches that include /FILE, indicating potential audio capture on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationMedium63Free2019-10-24Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationLow51Free2019-10-24Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium62Free2019-10-24Windows netsh Trace Start Command Execution
Flags netsh.exe launched with "trace" and "start", commonly used to begin a network trace capture on Windows.
Kutepov Anton, oscd.community, Huntrule TeamWindowsprocess_creationMedium237Free2019-10-24Windows Mshta.exe Launching JavaScript via Command Line
Detects Mshta.exe executions where the command line includes "javascript".
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh326Free2019-10-24