Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,073 rules
Cobalt Strike-style DNS Beaconing Queries (DNS)
Flags DNS queries with Cobalt Strike-style stage subdomain patterns used for covert beaconing.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsCritical81Free2018-05-10Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit
Flags registry changes to IFEO GlobalFlag and SilentProcessExit keys that can enable stealthy persistence or process redirection.
Karneades, Jonhnathan Ribeiro, Florian Roth, Huntrule TeamWindowsregistry_setHigh74Free2018-04-11Windows Process Creation: Access to Domain Group Policy in SYSVOL
Flags Windows processes that reference SYSVOL \policies paths in their command line.
Markus Neis, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium113Free2018-04-09Windows File Events: Known Offensive PowerShell Script File Creation
Alerts on creation of known offensive PowerShell/PowerShell module filenames on Windows.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Mustafa Kaan Demir, Georg Lauenstein, Huntrule TeamWindowsfile_eventHigh242Free2018-04-07Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh208Free2018-04-06Windows: Suspicious Process Spawning from Microsoft Office Applications
Alerts when Office apps spawn common execution tools or scripts from typical attacker staging paths on Windows.
Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io, Huntrule TeamWindowsprocess_creationHigh122Free2018-04-06Windows Proxy Activity Using Microsoft-WebDAV-MiniRedir GET User-Agent
Alerts on proxy HTTP GET requests using the Microsoft-WebDAV-MiniRedir/ User-Agent prefix associated with file download behavior.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh50Free2018-04-06Windows Ping Hex IP Usage via Command Line
Flags ping.exe executions that pass a hex-encoded IPv4 address (0x????????) in the command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2018-03-23Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Alerts on Windows service installation events for persistence-related scheduled services named SC Scheduled Scan or UpdatMachine.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssystemCritical91Free2018-03-23Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssecurityCritical216Free2018-03-23Windows Registry Persistence via UMe/UT Run Keys
Alerts on Windows registry changes to UMe/UT run key subpaths associated with persistence.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsregistry_eventCritical153Free2018-03-23Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Alerts when scheduled task and Service.exe processes launch autoit3.exe that runs nslookup TXT queries from a temp staging path.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationCritical229Free2018-03-23Windows Service Control Manager flags smbexec.py-style service installation via suspicious ImagePath
Flags suspicious Windows service installations matching a specific service name and BAT/delete command patterns in Event 7045.
Omer Faruk Celik, Huntrule TeamWindowssystemHigh83Free2018-03-20Windows Security: Registry NetNTLM Downgrade Configuration Changes
Alerts on Windows registry changes that weaken NetNTLM/NTLM security settings via LSA compatibility and restriction values.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowssecurityHigh118Free2018-03-20Windows Process Creation: taskmgr.exe launched in LOCAL_SYSTEM context
Flags taskmgr.exe process creation when initiated under a LOCAL_SYSTEM-equivalent user context string.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh31Free2018-03-18