Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,755 rules
Windows Scheduled Task Creation via PowerShell Using schtasks.exe with ONLOGON/DAILY/ONIDLE/HOURLY
Flags PowerShell-launched schtasks.exe /Create commands matching default PowerSploit/Empire scheduled task persistence behavior.
Markus Neis, @Karneades, Huntrule TeamWindowsprocess_creationHigh261Free2018-03-06Windows rundll32 Trojan Loader Execution via Local AppData and .dat Parameters
Flags rundll32.exe launched with AppData/local .dat and .dll patterns consistent with Trojan loader behavior.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh132Free2018-03-01Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Alerts when Winword spawns a FLTLDR.exe child process, matching a CVE-2017-0261-style exploit chain.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2018-02-22WinWord spawning MicroScMgmt.exe indicative of CVE-2015-1641 exploitation on Windows
Alerts when Winword.exe starts MicroScMgmt.exe, matching a known CVE-2015-1641 exploitation behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical151Free2018-02-22Linux syslog: Detect suspicious BIND/named error messages
Alerts on Linux syslog messages with BIND named fatal or denied DNS error strings.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsyslogHigh122Free2018-02-20Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.
Roberto Rodriguez (source), Dominik Schaudel (rule), Huntrule TeamWindowssecurityHigh80Free2018-02-12Windows File Creation: QuarksPwDump Credential Dump (.dmp) in Temp\SAM-*
Flags creation of QuarksPwDump .dmp dump files in Temp with a SAM-* filename pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical333Free2018-02-10Windows msiexec Process Creation With Web URL Parameters
Alerts when msiexec is launched with command-line web URL indicators in its parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium171Free2018-02-09Windows Process Creation: svchost Running NavShExt.dll Deletion/Setting Commands
Alerts on svchost.exe process commands referencing cached NavShExt.dll deletion and execution markers consistent with Elise backdoor activity.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical396Free2018-01-31Linux Auditd: Program Executions from Suspicious Web and Data Directories
Alerts on Linux process creation when the executed binary path begins with commonly abused temp/web/data directories.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdMedium173Free2018-01-23Linux auditd: Executing suspicious chmod and cp commands
Triggers on auditd EXECVE events for chmod (777/u+s) and cp overwriting /bin/ksh or /bin/sh.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdMedium101Free2017-12-12Windows System Binary Execution From Unusual Location (Process Creation)
Alerts when common Windows system binaries run from an uncommon directory rather than standard system locations.
Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh452Free2017-11-27Web/SQL Application Logs: SQL Error Strings Indicative of Injection Probing
Flags SQL error log messages with injection-probing syntax/quoting/UNION mismatch keywords.
Bjoern Kimminich, Huntrule TeamSqlapplicationHigh191Free2017-11-27Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Flags Windows process creation where EQNEDT32.EXE is the parent, matching CVE-2017-11882 exploitation dropper behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical364Free2017-11-23Windows Security Event 4719 Audit Policy Changes indicate Windows auditing disabled
Flags Windows Event Auditing disabled indicators from Security Event ID 4719 with removed success/failure audit policy.
"@neu5ron, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"WindowssecurityLow345Free2017-11-19