Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,087 rules
Windows: Suspicious Service Installation via Registry ImagePath Outside system32
Alerts on NalDrv/PROCEXP152 service ImagePath registry entries configured outside the expected system32 driver path.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsregistry_setMedium42Free2019-04-08Windows Suspicious PROCEXP152.sys Creation in Local Temp Folder
Flags creation of PROCEXP152.sys in AppData\Local\Temp, excluding events from common Sysinternals executables.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsfile_eventMedium209Free2019-04-08Windows Security Event 4673: SeLoadDriverPrivilege Use by Non-Whitelisted Processes
Flags Windows Event 4673 instances where SeLoadDriverPrivilege is exercised, suggesting attempts to load or unload kernel-mode drivers.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowssecurityMedium108Free2019-04-08Linux Command Lines Creating Symlink to /etc/passwd
Alerts on Linux command lines attempting to create symlinks to /etc/passwd via ln -s/ln -f patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High91Free2019-04-05WmiPrvSE.exe Spawned PowerShell Child Process on Windows
Alerts on PowerShell spawning from WmiPrvSE.exe, a possible indicator of WMI-based remote execution.
Markus Neis @Karneades, Huntrule TeamWindowsprocess_creationMedium73Free2019-04-03Windows Security 5145 Network Share Access to Sensitive File Extensions
Alerts when Windows users access network-shared files with extensions commonly targeted for credential or data collection.
Samir Bousseaden, Huntrule TeamWindowssecurityMedium362Free2019-04-03Windows GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Writes (Security 5136/5145)
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh126Free2019-04-03Windows Security 4661 Detects Privileged AD User/Group SID Enumeration via SAM
Identifies SAM_USER/SAM_GROUP access events (4661) aimed at privileged SIDs or names containing 'admin' while ignoring computer accounts.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh357Free2019-04-03Windows Security 5136: Modify AD ACL for DCSync Extended Right via ntSecurityDescriptor
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, Huntrule TeamWindowssecurityHigh274Free2019-04-03Windows Suspicious EXE in User Directory Launched by Microsoft Office Applications
Alert on Office spawning a .exe from C:\users\ (except when the child is Teams.exe).
Jason Lynch, Huntrule TeamWindowsprocess_creationHigh61Free2019-04-02Linux Suspicious Reverse Shell Command-Line Execution Patterns
Alerts on Linux command lines containing reverse-shell-style strings such as /dev/tcp redirections, netcat pipes, and socket connect patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High112Free2019-04-02Windows process creation matching EmpireMonkey-style jscript execution from Temp Errors.bat
Alerts on Windows executions that combine /e:jscript with a \Local\Temp\Errors.bat batch path.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh405Free2019-04-02Windows Security Logon Event ID 4800: Workstation Lock After Inactivity
Locked Workstation
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityInformational337Free2019-03-26Firewall Rule Accepting Cleartext Protocol Ports
Alerts on firewall-allowed traffic to common service ports that may carry credentials over unencrypted channels.
Alexandr Yampolskyi, SOC Prime, Tim Shelton, Huntrule TeamNetworkfirewallLow62Free2019-03-26Qualys Vulnerability Scans Indicating Default Credentials Use
Flags Qualys vulnerability scan results that indicate potential default credential usage on scanned hosts.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamQualys—Medium20Free2019-03-26