Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,061 rules
Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-03-19Windows Network Connections to Uncommon Ports (8080, 8888)
Flags Windows-initiated connections to ports 8080/8888 excluding private/local IPs and Program Files binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium147Free2017-03-19Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh83Free2017-03-19Windows network connection from process running in suspicious or uncommon file paths
Alerts on Windows network connections initiated by processes executing from suspicious or uncommon directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh209Free2017-03-19Windows UAC Bypass Indicator via sdclt Registry Key Manipulation
Alerts on registry set activity consistent with sdclt-related UAC bypass key manipulation.
Omer Yampel, Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh92Free2017-03-17Windows Security: Local Administrators Group Membership Change (Event 4732)
Flags Windows Event 4732 where a user is added to the local Administrators group.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium335Free2017-03-14Linux Log Shellshock Expression Pattern Matching
Identifies Shellshock-style function-body expressions in Linux log data via keyword string matches.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High309Free2017-03-14Windows PowerShell Web Access User-Agent Containing "WindowsPowerShell/" (Proxy Logs)
Alerts when proxy traffic shows a User-Agent containing "WindowsPowerShell/", consistent with PowerShell web access.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium131Free2017-03-13Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains
Finds proxy traffic requesting executable or script/doc payloads from hosts with suspicious TLDs not in the whitelist.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow62Free2017-03-13Windows Network Connections Initiated by PowerShell (powershell.exe or pwsh.exe)
Flags outbound network connections initiated by PowerShell on Windows, excluding common local and private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionLow80Free2017-03-13Windows PowerShell ScriptBlock with Encoded, Hidden, or Noninteractive Execution Parameters
Alerts on PowerShell ScriptBlockText containing encoded command, hidden window, or noninteractive execution parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2017-03-12Suspicious PowerShell Module Execution Using Encoded, Hidden, or Noninteractive Context (Windows)
Alerts on PowerShell module executions using encoded commands, hidden windows, or noninteractive flags to evade visibility and interaction.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleHigh167Free2017-03-12Windows BITSAdmin File Download via bitsadmin.exe with Transfer/Addfile Arguments
Flags bitsadmin.exe being started with parameters consistent with transferring/downloading files from an http URL.
Michael Haag, FPT.EagleEye, Huntrule TeamWindowsprocess_creationMedium289Free2017-03-09Windows Security: Detects SAM User/Group Access During Domain Recon (Event ID 4661)
Alerts on Event ID 4661 accesses to SAM user/group objects for domain Administrator and Domain Admins.
Florian Roth (Nextron Systems), Jack Croock (method), Jonhnathan Ribeiro (improvements), oscd.community, Huntrule TeamWindowssecurityHigh394Free2017-03-07Windows Service Install: NtsSrv (StoneDrill) via Service Control Manager Event 7045
Flags Windows service installs of NtsSrv by Service Control Manager with an ImagePath ending in " LocalService".
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh398Free2017-03-07