Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,748 rules
Windows PsExec Service Installation via Service Control Manager (Event ID 7045)
Flags Service Control Manager Event ID 7045 when a PSEXESVC service is installed with ImagePath ending in \PSEXESVC.exe.
Thomas Patzke, Huntrule TeamWindowssystemMedium161Free2017-06-12Windows Named Pipe Creation for PsExec Default Pipe
Alerts on creation of the default PsExec named pipe (\\PSEXESVC) using Windows named pipe creation telemetry.
Thomas Patzke, Huntrule TeamWindowspipe_createdLow120Free2017-06-12Windows Process Creation: Suspicious Execution of PlugX DLL Side-Loading Utilities from Uncommon Paths
Alerts on execution of PlugX-related helper binaries from atypical paths, excluding common legitimate directories.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2017-06-12Windows Process Creation: Fireball Archer installs via rundll32.exe and InstallArcherSvc
Flags rundll32.exe executions referencing InstallArcherSvc in the process command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2017-06-03Windows Registry Event: Pandemic implant key path contains null Instance
Detects registry activity targeting CurrentControlSet\services\null\Instance, associated with Windows implant persistence staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical81Free2017-06-01Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Alerts when RULER-labeled Windows Security events show NTLM auth (4776) plus 4624/4625 logons.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh297Free2017-05-31Windows Registry: DHCP Server Callout DLL and Enable Parameters Installation
Alerts on registry changes enabling and configuring DHCP Server callout DLLs via CalloutDlls and CalloutEnabled.
Dimitrios Slamaris, Huntrule TeamWindowsregistry_setHigh73Free2017-05-15Windows ETW: Kernel-General resets registry hive access bits in temp hive paths
Detects ETW EventID 16 when access bits are reset for Temp \SAM or \SECURITY hives.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh352Free2017-05-15Windows DHCP Server Error: Callout DLL Failed to Load
Flags DHCP Server events showing failure to load a configured Callout DLL (Event IDs 1031/1032/1034).
Dimitrios Slamaris, @atc_project (fix), Huntrule TeamWindowssystemHigh424Free2017-05-15Windows DHCP Server Loaded Callout DLL via Registry
Flags DHCP Server events where a registry-specified callout DLL is loaded (Event ID 1033), indicating potential persistence or execution.
Dimitrios Slamaris, Huntrule TeamWindowssystemHigh81Free2017-05-15Windows Backup Catalog Deleted (Microsoft-Windows-Backup Event ID 524)
Alerts when Windows deletes the backup catalog via Microsoft-Windows-Backup Event ID 524.
Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), Huntrule TeamWindowsapplicationMedium202Free2017-05-12Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll
Alerts on WER EventID 1001 crashes where MsMpEng.exe and mpengine.dll appear in the event data.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh101Free2017-05-09Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll
Alerts on Windows Application Error EventID 1000 indicating a crash involving MsMpEng.exe and mpengine.dll.
Florian Roth (Nextron Systems), Huntrule TeamWindowsapplicationHigh163Free2017-05-09Windows DNS ServerLevelPluginDll Registry Installation
Detects registry changes setting DNS ServerLevelPluginDll, which can enable malicious DNS plugin DLL loading after restart.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh385Free2017-05-08Windows: Detect dnscmd.exe setting ServerLevelPluginDll to install DNS plugin DLL
Flags dnscmd.exe DNS configuration that sets ServerLevelPluginDll, indicating potential malicious DNS server code injection.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2017-05-08