Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,069 rules
Windows System Binary Execution From Unusual Location (Process Creation)
Alerts when common Windows system binaries run from an uncommon directory rather than standard system locations.
Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh402Free2017-11-27Web/SQL Application Logs: SQL Error Strings Indicative of Injection Probing
Flags SQL error log messages with injection-probing syntax/quoting/UNION mismatch keywords.
Bjoern Kimminich, Huntrule TeamSqlapplicationHigh151Free2017-11-27Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Flags Windows process creation where EQNEDT32.EXE is the parent, matching CVE-2017-11882 exploitation dropper behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical364Free2017-11-23Windows Security Event 4719 Audit Policy Changes indicate Windows auditing disabled
Flags Windows Event Auditing disabled indicators from Security Event ID 4719 with removed success/failure audit policy.
"@neu5ron, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"WindowssecurityLow315Free2017-11-19Windows File Events: java.exe in AppData\Roaming\Oracle\bin Path with .exe and .vbs Artifacts
Alerts on Windows file events for suspicious java*.exe placement in AppData\Roaming\Oracle\bin and .vbs files containing "Retrive".
Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsfile_eventHigh435Free2017-11-10Windows Process Creation: javaw.exe Command Line Indicates Adwind/JRAT Roaming Oracle Path
Flags command-line patterns indicating javaw.exe execution from AppData\Roaming\Oracle with java/.exe markers.
Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2017-11-10Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Flags USB device plug/unplug related Driver Frameworks User-Mode events using Windows event IDs 2003, 2100, and 2102.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver-frameworkLow3210Free2017-11-09Proxy Downloads of Executables and Documents from Suspicious Dynamic DNS Domains
Alerts when proxy traffic downloads common executable or document payload types from a curated list of dynamic DNS hostnames.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium393Free2017-11-08Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Alerts when proxy users download common malware and lure file types from hosts using suspicious TLDs.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow365Free2017-11-07Windows Named Pipe Creation Alert for Known Malicious Pipe Names
Alert on Windows named pipe creations where the PipeName matches known malware-associated pipe identifiers.
Florian Roth (Nextron Systems), blueteam0ps, elhoim, Huntrule TeamWindowspipe_createdCritical86Free2017-11-06Windows Named Pipe Creation Matching Suspected Turla Pipe Names
Alert on Windows named pipe creation when the PipeName matches Turla-associated strings.
Markus Neis, Huntrule TeamWindowspipe_createdCritical401Free2017-11-06Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Alerts on remote logons to admin-named accounts in Windows Security logs (4624, LogonType 10, Negotiate).
juju4, Huntrule TeamWindowssecurityLow304Free2017-10-29Proxy Web Requests for Flash Player Installer from Unofficial Locations
Flags proxy downloads for Flash Player installer paths when the request host is not ending in .adobe.com.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh93Free2017-10-25Windows: Detect Renamed ps.exe Executing netstat via cmd /c
Alerts on Windows executions of renamed PsTool-like ps.exe that include accept-eula and netstat via cmd.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh286Free2017-10-22Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Flags Word (WINWORD.EXE) spawning csc.exe, a suspicious execution pattern observed in some exploit chains.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical41Free2017-09-15