Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,059 rules
Windows PowerShell Script Block Logging: PSAttack marker string
Alerts when PowerShell script blocks contain the "PS ATTACK!!!" marker on Windows.
Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh344Free2017-03-05Windows PowerShell Script Block Contains Exploitation Framework and Credential Theft Keywords
Alerts on PowerShell script block text containing known exploitation, token, and memory-related keywords.
Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptMedium168Free2017-03-05Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Alerts when PowerShell ScriptBlock text includes strings matching known malicious commandlets from common exploitation toolsets.
Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer, Huntrule TeamWindowsps_scriptHigh424Free2017-03-05Suspicious PowerShell Module Usage with Hidden/Encoded Execution Parameters on Windows
Flags hidden or encoded PowerShell invocations that decode/execute code or download-and-execute patterns, while filtering a Chocolatey installer snippet.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowsps_moduleHigh295Free2017-03-05Suspicious PowerShell WebClient Downloads via PoshModule
Alerts on PowerShell module activity referencing System.Net.WebClient with DownloadFile/DownloadString calls to fetch remote content.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_moduleMedium101Free2017-03-05Windows PowerShell Execution via EngineVersion/HostVersion Mismatch in Command Start Telemetry
Detects PowerShell execution attempts that match a specific executable EngineVersion/HostVersion mismatch pattern on Windows.
Sean Metcalf (source), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_classic_startHigh92Free2017-03-05PowerShell Net.WebClient DownloadFile/DownloadString Usage (Classic)
Flags PowerShell Classic commands using Net.WebClient to download content via DownloadFile or DownloadString.
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_classic_startLow233Free2017-03-05Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Flags Service Control Manager service creation with ImagePath names tied to credential dumping tools (Event ID 7045).
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssystemHigh121Free2017-03-05Windows Security EID 4697 Service Execution of Credential Dumping Tools
Alerts on Event ID 4697 service execution paths containing common credential dumping tool names on Windows.
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssecurityHigh422Free2017-03-05Windows: Detects Access to ADMIN$ Network Share (Event 5140)
Alerts on Windows Security event 5140 entries where an access request targets the ADMIN$ share.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityLow104Free2017-03-04Windows process access targeting verclsid.exe with Office/VBA shellcode traces
Flags broad access to verclsid.exe from Microsoft Office/VBA contexts with VBE7.DLL call traces consistent with shellcode injection.
John Lambert (tech), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh106Free2017-03-04Linux Syslog Buffer Overflow Exploit Attempt Keywords
Alerts on Linux syslog entries containing known buffer overflow/stack-smashing attempt keyword patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High2310Free2017-03-01Linux ClamAV alerts for Trojan, Webshell, Rootkit, Htran, VirTool detections
Detects ClamAV log entries with keyword-based indicators for Trojans, webshells, rootkits, and Htran.
Florian Roth (Nextron Systems), Huntrule TeamLinuxclamavHigh142Free2017-03-01Apache worker crash logs with "Segmentation Fault" exit signal
Alerts on Apache error log lines showing a worker process crashed with an exit signal Segmentation Fault.
Florian Roth (Nextron Systems), Huntrule TeamWebapacheHigh325Free2017-02-28Windows LSASS Remote Thread Creation Indicative of Password Dumping
Flags Windows remote thread creation targeting lsass.exe, a common pattern in password dumping activity.
Thomas Patzke, Huntrule TeamWindowscreate_remote_threadHigh427Free2017-02-19