Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,748 rules
Windows DNS Server error when loading ServerLevelPlugin DLL fails
Flags Windows DNS Server errors where the ServerLevelPluginDLL plugin DLL fails to load.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns-serverHigh411Free2017-05-08Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2017-04-15Firewall Alerts for C2 IP Traffic to 69.42.98.86 and 89.185.234.145
Alerts when firewall traffic involves the two specified IPs associated with presumed C2 communication.
Florian Roth (Nextron Systems), Huntrule Team—firewallHigh376Free2017-04-15Windows Security: AD user/computer backdoor via msDS-AllowedToDelegateTo and delegation attributes
Alerts on AD delegation-related attribute changes that may create credentialless account control paths.
"@neu5ron, Huntrule Team"WindowssecurityHigh198Free2017-04-13PowerShell Credential Prompt via PromptForCredential
Flags PowerShell scripts that reference "PromptForCredential", indicating credential prompt behavior in Script Block Logging.
John Lambert (idea), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh409Free2017-04-09Linux Command-Line Indicators of Equation Group Tooling
Flags execution of known suspicious Linux shell command patterns tied to Equation Group-style scripting and tooling.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High152Free2017-04-09Windows CScript and csvde Command-Line Execution Patterns Suggesting Cloud Hopper Activity
Detects cscript VBScript shell execution and csvde writing log files into C:\windows\web\.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2017-04-07Windows Service Install (Event ID 7045) for srservice, ipvpn, hkmsvc
Alerts on Windows service creation events (7045) for srservice, ipvpn, and hkmsvc service names.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh131Free2017-03-31Windows Service Creation: ServiceName javamtsup (Event ID 4697)
Flags Windows Security Event 4697 when a service named "javamtsup" is installed, indicating potential persistence.
Florian Roth (Nextron Systems), Daniil Yugoslavskiy, oscd.community (update), Huntrule TeamWindowssecurityCritical112Free2017-03-27Linux Log File Alerts for Suspicious Messages
Generates alerts when Linux log text contains suspicious keywords indicating possible network, service, or logging disruption.
Florian Roth (Nextron Systems), Huntrule TeamLinux—Medium81Free2017-03-25PowerShell downgrade indicators via EngineVersion=2. and HostVersion !=2. (Windows)
Detects PowerShell version mismatches that may indicate a downgrade attempt using EngineVersion vs HostVersion telemetry.
Florian Roth (Nextron Systems), Lee Holmes (idea), Harish Segar (improvements), Huntrule TeamWindowsps_classic_startMedium418Free2017-03-22Windows Registry UAC Bypass via Event Viewer Command Key (mscfile shell open command)
Alerts on registry changes to the mscfile shell open command key consistent with an Event Viewer UAC bypass technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setHigh151Free2017-03-19Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2017-03-19Windows Network Connections to Uncommon Ports (8080, 8888)
Flags Windows-initiated connections to ports 8080/8888 excluding private/local IPs and Program Files binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium167Free2017-03-19Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh93Free2017-03-19