Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,127 rules
Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Alerts on Windows Security failures for Kerberos TGT-related operations using specific Kerberos event IDs and status codes.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh271Free2017-02-10Windows Kerberos Service Tickets Requesting RC4 Encryption (EventID 4769)
Flags Windows Kerberos service ticket requests using RC4 encryption while excluding '$' machine/service accounts.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium275Free2017-02-06Windows Event Logs: Mimikatz Keyword Indicators
Detects Mimikatz-related keywords in Windows event logs while filtering Sysmon EventID 15 to limit noise.
Florian Roth (Nextron Systems), David ANDRE (additional keywords), Huntrule TeamWindows—High427Free2017-01-10Windows Event Log Cleared (Microsoft-Windows-Eventlog EventID 104)
Alerts when Windows event logs are cleared, based on Microsoft-Windows-Eventlog Event ID 104 from System telemetry.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemMedium181Free2017-01-10Windows Security and Eventlog Cleared via Event IDs 517 or 1102
Flags Windows event log clearing using Security Event ID 517 and Microsoft-Windows-Eventlog Event ID 1102.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh368Free2017-01-10Windows Webshell Recon Command-Line Keywords via Web Server Processes
Flags Windows process chains where web server parents spawn reconnaissance- and execution-related command lines indicative of webshell activity.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson, Huntrule TeamWindowsprocess_creationHigh307Free2017-01-01Windows WerFault Access to lsass.exe Indicative of Credential Dumping Attempts
Alert on WerFault.exe gaining broad access to lsass.exe, consistent with credential dumping attempts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh203Free2012-06-27