Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,751 rules
Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Alerts when proxy users download common malware and lure file types from hosts using suspicious TLDs.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyLow425Free2017-11-07Windows Named Pipe Creation Alert for Known Malicious Pipe Names
Alert on Windows named pipe creations where the PipeName matches known malware-associated pipe identifiers.
Florian Roth (Nextron Systems), blueteam0ps, elhoim, Huntrule TeamWindowspipe_createdCritical116Free2017-11-06Windows Named Pipe Creation Matching Suspected Turla Pipe Names
Alert on Windows named pipe creation when the PipeName matches Turla-associated strings.
Markus Neis, Huntrule TeamWindowspipe_createdCritical431Free2017-11-06Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Alerts on remote logons to admin-named accounts in Windows Security logs (4624, LogonType 10, Negotiate).
juju4, Huntrule TeamWindowssecurityLow324Free2017-10-29Proxy Web Requests for Flash Player Installer from Unofficial Locations
Flags proxy downloads for Flash Player installer paths when the request host is not ending in .adobe.com.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh113Free2017-10-25Windows: Detect Renamed ps.exe Executing netstat via cmd /c
Alerts on Windows executions of renamed PsTool-like ps.exe that include accept-eula and netstat via cmd.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh326Free2017-10-22Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Flags Word (WINWORD.EXE) spawning csc.exe, a suspicious execution pattern observed in some exploit chains.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical71Free2017-09-15Windows Registry Key Created: Sysinternals EULA Acceptance
Flags registry writes indicating Sysinternals EULA acceptance via a TargetObject ending with \EulaAccepted.
Markus Neis, Huntrule TeamWindowsregistry_setLow110Free2017-08-28Windows: Command-line execution using Sysinternals -accepteula flag
Alerts on Windows processes launched with the -accepteula flag, often associated with Sysinternals tool execution.
Markus Neis, Huntrule TeamWindowsprocess_creationLow142Free2017-08-28Linux JexBoss Suspicious Bash Command Launch with /dev/tcp
Flags Linux executions containing bash -c /bin/bash paired with /dev/tcp/ indicative of a reverse-shell command sequence.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High458Free2017-08-24sshd Buffer Underflow Error Message Matching CVE-2018-15473 Exploit Attempt (Linux)
Flags Linux sshd pre-auth buffer parsing error messages that align with CVE-2018-15473 exploit attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsshdMedium344Free2017-08-24Windows WMI Persistence via Event Filter/Consumer Bindings and Filter Registration
Flags likely WMI-based persistence by spotting event filter/consumer bindings and WMI filter registrations tied to script/command-line consumers.
Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule TeamWindowswmiMedium234Free2017-08-22Windows WMI Persistence via Security Event 4662 on WMI subscription namespace
Alerts on Security Event 4662 indicating access to WMI Namespace objects with "subscription" in the name.
Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule TeamWindowssecurityMedium81Free2017-08-22Linux Suspicious Shell Command Lines for Exploit/Payload Delivery
Detects Linux command-line strings matching wget/piping, payload staging, permission changes, and socat/HTTP server execution patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High4510Free2017-08-21Windows svchost.exe Spawned by Uncommon Parent Process
Alerts when svchost.exe starts with an unusual parent process name on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2017-08-15