Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,075 rules
Windows: .NET Reflection Attempt to Disable AMSI via amsiInitFailed
Alerts on Windows command lines referencing amsiInitFailed and .NET reflection patterns to disable AMSI scanning.
Markus Neis, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh422Free2018-08-17DNS TXT Answers Containing Command Execution Keywords (IEX, Invoke-Expression, cmd.exe)
Alerts on DNS TXT answers containing IEX/Invoke-Expression or cmd.exe strings indicative of execution-oriented payloads.
Markus Neis, Huntrule TeamNetworkdnsHigh133Free2018-08-08PowerShell NTFS Alternate Data Stream Writes via set-content/add-content
Alerts on PowerShell Set/Add-Content operations that specify -Stream, indicating potential NTFS Alternate Data Stream writes.
Sami Ruohonen, Huntrule TeamWindowsps_scriptHigh262Free2018-07-24Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
Markus Neis, Huntrule TeamWindowsfile_eventHigh203Free2018-07-24Web server access to WebLogic keystore JavaScript webshell URLs
Flags web requests attempting to access JavaScript content within a WebLogic keystore path.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical271Free2018-07-22Windows Registry Explorer Run Key Persistence Pointing to Suspicious Paths
Alerts on writes to the Explorer Run policy registry key with details pointing to suspicious filesystem paths.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsregistry_setHigh122Free2018-07-18Windows Registry Events: CMSTP Execution via cmmgr32.exe TargetObject
Flags registry events referencing \cmmgr32.exe, consistent with CMSTP-related execution behavior on Windows.
Nik Seetharaman, Huntrule TeamWindowsregistry_eventHigh71Free2018-07-16Windows CMSTP Process Spawning Child Process
Alerts on child processes spawned by Windows cmstp.exe, a common signal for CMSTP abuse.
Nik Seetharaman, Huntrule TeamWindowsprocess_creationHigh226Free2018-07-16Windows Process Access to cmlua.dll by CMSTP Connection Manager Profile Installer
Alerts on Windows process access events whose call trace includes cmlua.dll, indicating potential CMSTP-related execution.
Nik Seetharaman, Huntrule TeamWindowsprocess_accessHigh418Free2018-07-16Windows PowerShell Remote Thread Creation Into Uncommon Target Processes
Alerts on PowerShell creating remote threads in rundll32.exe or regsvr32.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_remote_threadMedium165Free2018-06-25Windows Sysprep Execution Targeting AppData Directory
Alerts when sysprep.exe runs with an AppData directory present in the command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium73Free2018-06-22Windows NTLM authentication events (Event ID 8002)
Alerts on Windows NTLM authentication occurrences based on Event ID 8002 from Microsoft-Windows-NTLM/Operational.
Florian Roth (Nextron Systems), Huntrule TeamWindowsntlmLow1810Free2018-06-08Windows Process Creation: svchost.exe Spawns mshta.exe (LethalHTA)
Alerts on Windows instances where svchost.exe spawns mshta.exe, indicating potential LethalHTA execution.
Markus Neis, Huntrule TeamWindowsprocess_creationHigh83Free2018-06-07Suspicious Telegram API proxy access without Telegram User-Agent
Alerts on api.telegram.org requests where the User-Agent lacks common Telegram bot identifiers.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium72Free2018-06-05Suspicious DNS queries to api.telegram.org for Telegram Bot API traffic
Flags DNS queries to api.telegram.org that may indicate Telegram Bot API usage by bots or malware.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsMedium97Free2018-06-05