Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,093 rules
Linux Service Reload/Start via systemctl or service Command Execution
Identifies Linux process executions invoking service control commands with start or reload keywords.
Jakob Weinzettl, oscd.community, CheraghiMilad, Huntrule TeamLinuxauditdLow185Free2019-09-23Linux auditd: chmod/chown process execution indicating file or folder permission changes
Flags Linux EXECVE events running chmod or chown, which commonly correspond to file/folder permission changes.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdLow264Free2019-09-23Linux auditd: Detect chattr -i removing immutable file attribute
Flags Linux processes using chattr to remove the immutable (-i) file attribute via auditd execve telemetry.
Jakob Weinzettl, oscd.community, Huntrule TeamLinuxauditdMedium62Free2019-09-23Windows Registry: Enable WDigest UseLogonCredential (Use clear-text logon credential setting)
Flags registry writes that enable WDigest UseLogonCredential, turning on potential clear-text credential storage.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh193Free2019-09-12Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Alerts when wsmprovhost.exe is seen as a process or parent process, indicating remote PowerShell via WinRM.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium40Free2019-09-12Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents
Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.
Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements), Huntrule TeamWindowsprocess_creationLow81Free2019-09-12Windows Named Pipe Created for PowerShell PSHost Instance
Alerts on named pipe creation with a \PSHost prefix, indicating PowerShell host-related activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspipe_createdInformational30Free2019-09-12Windows Named Pipe Creation: Alternate PowerShell Host via \PSHost
Alerts on creation of \PSHost named pipes to identify alternate PowerShell host usage via Windows pipe events.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowspipe_createdMedium52Free2019-09-12Windows: WinRM inbound network connections to ports 5985/5986 for PowerShell remoting
Alerts on WinRM inbound connections (ports 5985/5986) consistent with remote PowerShell remoting activity.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh373Free2019-09-12Windows Security: Detect WRITE_DAC on AD DS objects (Event ID 4662)
Flags AD DS Security Event 4662 activity indicating WRITE_DAC permission changes on domain objects.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical101Free2019-09-12Windows Suspicious Debugger Registration via Image File Execution Options
Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh82Free2019-09-06Windows Process Creation: Empire PowerShell UAC Bypass CommandLine Pattern
Flags Windows process creation events running Empire-style PowerShell UAC bypass command fragments.
Ecco, Huntrule TeamWindowsprocess_creationCritical61Free2019-08-30Windows Registry: Modification of WDigest IsCredGuardEnabled to Disable Credential Guard
Alerts on Windows registry changes to WDigest\IsCredGuardEnabled that may disable Credential Guard.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh205Free2019-08-25PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)
Flags PowerShell command lines containing FromBase64String along with base64-encoded UTF-16 marker patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh72Free2019-08-24Windows: Alert on csc.exe Executing from User-Writable or Suspicious Paths
Alerts when csc.exe is launched from user/temp-like paths, indicating potential on-the-fly .NET compilation.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2019-08-24