Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,093 rules
Windows PowerShell Base64 Command Line Executing IEX
Identifies Windows PowerShell processes with Base64-encoded command-line content that contains an IEX execution pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2310Free2019-08-23Windows: WmiPrvSE.exe Spawning a Child Process
Identifies child processes created by WmiPrvSE.exe on Windows, highlighting potential WMI-based execution attempts.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium72Free2019-08-15Windows Security: Non-System SeTakeOwnershipPrivilege granted on SCM database object
Flags non-system users requesting SeTakeOwnershipPrivilege on the SCM database object servicesactive in Windows Security 4674.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowssecurityMedium121Free2019-08-15Cisco AAA commands: shutdown or config-register changes to boot into alternate modes
Flags Cisco AAA events referencing shutdown or config-register 0x2100/0x2142 changes that may disrupt boot or availability.
Austin Clark, Huntrule TeamCiscoaaaMedium113Free2019-08-15Windows Security: SysKey-related LSA Registry Key Access (4656/4663)
Alerts on access to LSA registry keys used to compute SysKey based on Windows Security handle and registry object events.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh142Free2019-08-12Windows Security Event 4656: Non-system handle failure to SCM database object
Alerts on failed SCM database handle requests for ServicesActive from non-system logons using Windows Security Event ID 4656.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium213Free2019-08-12Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Flags Windows handle requests to registry keys ending with \SAM using Security EventID 4656.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh112Free2019-08-12Cisco AAA keyword hits for data staging and file transfer commands (TFTP/RCP/PUT/COPY/ARCHIVE)
Flags Cisco AAA activity containing TFTP/RCP and copy/archive commands commonly used to stage data on devices.
Austin Clark, Huntrule TeamCiscoaaaLow435Free2019-08-12Cisco AAA Configuration Modification Command Patterns
Flags Cisco AAA command activity that includes keywords for configuration changes like HTTP/HTTPS, KRON, ACLs, and NTP.
Austin Clark, Huntrule TeamCiscoaaaMedium121Free2019-08-12Cisco AAA local account and remote authentication changes
Flags Cisco AAA log events showing local username/account changes and remote authentication configuration updates.
Austin Clark, Huntrule TeamCiscoaaaHigh382Free2019-08-12Cisco AAA Commands Indicating File Deletion on Local Flash Storage
Flags Cisco AAA log entries referencing flash file erase, delete, or format operations that may indicate stealthy cleanup.
Austin Clark, Huntrule TeamCiscoaaaMedium359Free2019-08-12Cisco AAA discovery via show/dir commands
Alerts on Cisco AAA log entries with discovery-oriented 'dir' and 'show' command keywords.
Austin Clark, Huntrule TeamCiscoaaaLow229Free2019-08-12Cisco IOS AAA Crypto PKI Export/Import Commands
Alerts on Cisco IOS AAA logs showing crypto PKI export of private keys or PKI import of certificates/trustpoints.
Austin Clark, Huntrule TeamCiscoaaaHigh265Free2019-08-12Cisco Network OS Log and Archive Clearing via “clear logging” Commands
Flags Cisco network OS attempts to clear logs or archives via AAA command text.
Austin Clark, Huntrule TeamCiscoaaaHigh224Free2019-08-12Cisco AAA configuration changes enabling SPAN/RSPAN monitoring capture
Alerts on Cisco AAA logs referencing SPAN/RSPAN or monitor capture point configuration changes.
Austin Clark, Huntrule TeamCiscoaaaMedium62Free2019-08-11