Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
146 rules
Windows DNS Query for _ldap.* Using LDAP-Related Discovery
Alerts on _ldap.* DNS queries from uncommon Windows processes, indicating potential LDAP/DNS service discovery.
frack113, Huntrule TeamWindowsdns_queryLow141Free2022-08-20Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2210Free2022-08-02Linux Process Recon: Find SUID/htpasswd Files via Command-Line Patterns
Flags Linux command-line reconnaissance patterns for .htpasswd discovery and setuid (-perm -4000) file enumeration.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh348Free2022-06-20Windows Process Creation: Sysinternals PsService (PsService*.exe) Execution
Alerts on execution of Sysinternals PsService (PsService*.exe) on Windows, which can support service discovery and tampering.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium4110Free2022-06-16Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
frack113, Huntrule TeamWindowsps_scriptLow111Free2022-06-04Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)
Flags process executions of gpresult.exe that request RSoP details using /z and /v on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium476Free2022-05-01Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
frack113, Huntrule TeamWindowsps_scriptLow153Free2022-04-04Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
frack113, Huntrule TeamWindowsps_scriptLow133Free2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
frack113, Huntrule TeamWindowsps_scriptLow404Free2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
frack113, Huntrule TeamWindowsps_scriptLow357Free2022-03-17Windows CHCP Console Code Page Lookup Triggered From cmd.exe
Flags cmd.exe-launched chcp.com executions likely used to query system code page/locale for discovery.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationMedium192Free2022-02-21Microsoft 365 eDiscovery PST Export or Search Started Success Alert
Alerts on successful eDiscovery search/export activity that produces PST files in Microsoft 365.
Sorina Ionescu, Huntrule TeamM365threat_managementMedium336Free2022-02-08Windows Process Command Line Network Recon via nslookup LDAP SRV Query
Identifies Windows command lines running nslookup with an LDAP SRV domain controller discovery query string.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-02-07Windows Process Creation: Suspicious systeminfo.exe Execution
Alerts on execution of systeminfo.exe (or sysinfo.exe) via Windows process creation logs for system discovery.
frack113, Huntrule TeamWindowsprocess_creationLow153Free2022-01-01Windows: Suspicious Process Execution of hostname.exe
Flags execution of hostname.exe from process creation events on Windows for discovery activity.
frack113, Huntrule TeamWindowsprocess_creationLow111Free2022-01-01