Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,100 rules
Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Alerts when Hwp.exe launches gbb.exe, a suspicious child process pattern on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2019-10-24Windows hh.exe Execution Triggered by .chm Command Line
Flags hh.exe being executed with a command line referencing a .chm file on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community, Huntrule TeamWindowsprocess_creationLow93Free2019-10-24Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
E.M. Anhaus, Tony Lambert, oscd.community, omkar72, Huntrule TeamWindowsprocess_creationMedium221Free2019-10-24Windows Execution of dnscat2 and iodine DNS Exfiltration/Tunneling Tools
Flags Windows execution of DNS tunneling/exfiltration tools identified by iodine.exe or dnscat2 in process creation events.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh193Free2019-10-24Windows Boot Configuration Tampering via bcdedit.exe
Flags bcdedit.exe commands that set boot status policy to ignore failures and disable recovery (recoveryenabled=no).
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2019-10-24Windows at.exe Interactive Job via Process Creation
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh143Free2019-10-24Windows PowerShell ScriptBlock Web Request Cmdlets and Command-Line Tools
Alerts when PowerShell script blocks reference web request and download cmdlets/commands, excluding a specific guest configuration path.
James Pemberton / @4A616D6573, Huntrule TeamWindowsps_scriptMedium122Free2019-10-24Windows: Uncommon Outbound Kerberos Traffic on Port 88
Alerts on initiated outbound connections to Kerberos TCP/88 from unexpected Windows processes.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowsnetwork_connectionMedium199Free2019-10-24Windows PowerShell Profile File Creation or Modification
Alerts on creation or modification of PowerShell profile.ps1 files in typical Windows and PowerShell 7 locations.
HieuTT35, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium133Free2019-10-24Windows Service Control Manager TAP Driver Installation (tap0901)
Flags Windows service installation events for TAP driver image paths containing 'tap0901'.
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowssystemMedium82Free2019-10-24Windows Security 4673: Failed LsaRegisterLogonProcess Handle Registration
Alerts on failed attempts to call LsaRegisterLogonProcess() in Windows Security (Event 4673), tied to the SeTcbPrivilege requirement.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh134Free2019-10-24Windows Security 4697: TAP Driver Service Installation (tap0901)
Alerts on Windows Security EID 4697 service installation events for TAP driver files containing "tap0901."
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowssecurityLow133Free2019-10-24Uncommon Outbound Kerberos Port 88 Network Connections (Windows Security Event 5156)
Alerts on rare outbound Kerberos (port 88) connections from non-browser/non-lsass processes using Windows Event 5156.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowssecurityMedium3110Free2019-10-24Windows Security 4611: Rubeus-Indicative New Trusted Logon Process Registration
Alerts on Windows Security Event 4611 registering a new trusted logon process named 'User32LogonProcesss'.
Roberto Rodriguez (source), Ilyas Ochkov (rule), oscd.community, Huntrule TeamWindowssecurityHigh131Free2019-10-24Linux: Detect Modification of /etc/ld.so.preload for Shared Object Injection
Flags auditd activity where /etc/ld.so.preload is modified, indicating potential shared object injection.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamLinuxauditdHigh82Free2019-10-24