Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows MSSQL Failed Logon (EventID 18456) From External Client IP
Alerts on MSSQL failed login attempts (Event 18456) from client IPs outside typical local/private ranges.
j4son, Huntrule TeamWindowsapplicationMedium103Free2023-10-11Windows MSSQL Failed Logon (Event ID 18456) Detection
Alerts on MSSQL-related failed login attempts (Event ID 18456) captured in Windows application logs.
Nasreddine Bencherchali (Nextron Systems), j4son, Huntrule TeamWindowsapplicationLow80Free2023-10-11O365 Mail Forwarding and Redirecting Rule Changes
Identifies O365 mailbox/inbox rule changes that configure forwarding or redirects in audit logs.
RedCanary Team (idea), Harjot Singh @cyb3rjy0t, Huntrule TeamM365auditMedium60Free2023-10-11Windows: Suspicious HTA Startup Folder Creation by FoxitPDFReader.exe
Alerts on FoxitPDFReader.exe creating .hta files in the Startup Programs folder, which can indicate persistence.
Gregory, Huntrule TeamWindowsfile_eventHigh1810Free2023-10-11Windows ScreenConnect RMM System Command Execution via cmd.exe
Flags cmd.exe launched by ScreenConnect.ClientService.exe with a TEMP\ScreenConnect command-line path.
Ali Alwashali, Huntrule TeamWindowsprocess_creationLow131Free2023-10-10Windows: ScreenConnect Temporary File Creation in ConnectWiseControl Temp
Flags file writes to ScreenConnect’s ConnectWiseControl\Temp staging directory from ScreenConnect.WindowsClient.exe.
Ali Alwashali, Huntrule TeamWindowsfile_eventLow82Free2023-10-10Windows Application: ScreenConnect RMM File Transfer Activity (Event 201)
Flags ScreenConnect RMM file transfer events on Windows based on provider name, Event ID 201, and transfer action text.
Ali Alwashali, Huntrule TeamWindowsapplicationLow154Free2023-10-10Windows ScreenConnect Remote Command Execution (EventID 200)
Detects ScreenConnect command execution on Windows by matching EventID 200 with an 'Executed command of length' message.
Ali Alwashali, Huntrule TeamWindowsapplicationLow133Free2023-10-10Windows Process Creation: CLI CommandLine References NTFS ::$index_allocation Stream
Flags Windows CLI commands referencing the NTFS ::$index_allocation stream for potential hidden directory activity.
Nasreddine Bencherchali (Nextron Systems), Scoubi (@ScoubiMtl), Huntrule TeamWindowsprocess_creationMedium121Free2023-10-09Windows Hidden Directory Creation Using NTFS $INDEX_ALLOCATION Stream
Alerts on Windows file events creating hidden NTFS content using the '::$index_allocation' alternate stream.
Scoubi (@ScoubiMtl), Huntrule TeamWindowsfile_eventMedium389Free2023-10-09Windows Kerberos KDC: Certificate used without strong user mapping
Alerts on Windows KDC certificate validation events lacking strong certificate-to-user mapping (Event 39/41).
"@br4dy5, Huntrule Team"WindowssystemMedium214Free2023-10-09Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary
Flags Windows process executions that match renamed VS Code tunnel invocation patterns and related internal service startup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2023-09-28Windows Service Registry Key ReadControl Access (Event ID 4663)
Flags READ_CONTROL access requests to service registry keys (\SYSTEM\ControlSet\Services\) via Windows Security Event 4663.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowssecurityLow153Free2023-09-28AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
Detects CloudTrail identity center events that associate or change the external identity provider configuration.
Michael McIntyre @wtfender, Huntrule TeamAwscloudtrailHigh112Free2023-09-27Windows Registry Scheduled Task Cache Key Creation Detection
Flags registry event activity under Scheduled TaskCache indicating scheduled task creation or updates on Windows.
Center for Threat Informed Defense (CTID) Summiting the Pyramid Team, Huntrule TeamWindowsregistry_eventLow80Free2023-09-27