Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,096 rules
Windows: Detect sc.exe Service Config binPath Changes to Suspicious Commands/Paths
Alerts when sc.exe updates a service binPath to point at suspicious commands or commonly abused directories.
Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2019-10-21Windows reg.exe Registry Query Reconnaissance (Process Creation)
Alerts on reg.exe process executions performing registry queries against high-value configuration and service keys.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium4310Free2019-10-21Windows Rar.exe Files Added to Archive Activity
Alerts when Windows rar.exe is used to add files to an archive using the " a " command-line pattern.
Timur Zinniatullin, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationLow169Free2019-10-21Windows: net.exe used to start a service with the start flag
Identifies Windows processes using net.exe/net1.exe with ' start ' to start services.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21Windows Msxsl.exe Execution
Flags execution of the Windows MSXSL utility (msxsl.exe), which can be abused to process attacker-controlled XSL inputs.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium70Free2019-10-21Windows Process: File Association Changes via assoc Command
Alerts on cmd.exe launches running the assoc command to modify Windows default file associations.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21PowerShell ScriptBlock Winlogon Registry Modification via CurrentVersion\Winlogon
Detects PowerShell script blocks that modify Winlogon helper registry keys via Set-ItemProperty or New-Item on Windows.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium92Free2019-10-21Suspicious Crypto Miner User Agents in Proxy Logs
Flags proxy requests with User-Agent prefixes tied to XMRig or CCMiner crypto miners.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh267Free2019-10-21Linux System Owner or User Discovery via Common Utility Execution
Flags execution of Linux user/system identification utilities such as whoami and id.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow366Free2019-10-21Linux: Detect execution of tcpdump or tshark with interface (-i) capture option
Alerts on tcpdump or tshark executions on Linux where an interface flag is present, consistent with network sniffing.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow438Free2019-10-21Linux Masquerading via crond Path Using cp Launching /bin/sh
Alerts on Linux execve where cp runs through /bin/sh and the argument ends with /crond, indicating potential masquerading.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdMedium60Free2019-10-21Linux Auditd: Command Execution of zip, gzip -k, or tar -c for Data Compression
Alerts on Linux execve events launching zip, gzip (-k), or tar create commands often used to compress data.
Timur Zinniatullin, oscd.community, Huntrule TeamLinuxauditdLow81Free2019-10-21PowerShell Compress-Archive Cmdlet Execution for Data Compression
Flags PowerShell scripts using the Compress-Archive cmdlet, consistent with local data packaging before collection or exfiltration.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptLow50Free2019-10-21Windows Process Creation: Suspicious Command-Line Parameters for 7-Zip/RAR Executables
Detects 7z/rar executions on Windows with suspicious switches like password and delete options.
Florian Roth (Nextron Systems), Samir Bousseaden, Huntrule TeamWindowsprocess_creationMedium30Free2019-10-15Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Alerts on Linux process command lines containing ' -u#' indicative of sudo CVE-2019-14287 exploitation attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh155Free2019-10-15