Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
407 rules
Windows Cmd.exe: SET /p file append/override pattern via set /p=
Alerts on Cmd.exe command lines containing SET /p= syntax that may be used with redirection to modify file contents.
Nasreddine Bencherchali (Nextron Systems), MahirAli Khan (in/mahiralikhan), Huntrule TeamWindowsprocess_creationLow100Free2024-08-22Windows Registry Set Internet Settings ZoneMap Proxy and Intranet Values
Alerts on Windows ZoneMap registry changes that set proxy/intranet bypass values, using registry set-value telemetry and process image context.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setLow398Free2024-07-31Windows: Uncommon Process Access to Chromium User Data Cookies and History
Alerts on uncommon executables reading Chromium cookies/history/web data on Windows, excluding common system and installer paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessLow100Free2024-07-29Windows File Access Attempt to Panther\unattend.xml During Unattended Install
Alerts on attempts to access Panther\unattend.xml on Windows, a potential source of embedded credentials.
frack113, Huntrule TeamWindowsfile_accessLow110Free2024-07-22Windows Process Execution of BitLockerToGo.EXE
Alerts on Windows execution of BitLockerToGo.exe, a rarely used BitLocker To Go component for portable drive encryption.
Josh Nickels, mttaggart, Huntrule TeamWindowsprocess_creationLow4010Free2024-07-11AWS CloudTrail: CreateNetworkAclEntry Adds Network ACL Rules
Identifies when EC2 network ACL entries are created in AWS via CloudTrail.
jamesc-grafana, Huntrule TeamAwscloudtrailLow152Free2024-07-11Windows: Microsoft Word Loads WLL Add-In Files
Flags Microsoft Word loading a .wll add-in module on Windows using image load telemetry.
Steffen Rogge (dr0pd34d), Huntrule TeamWindowsimage_loadLow110Free2024-07-10Windows Process Access to Uncommon Target Images Using PROCESS_ALL_ACCESS
Alerts on Windows events granting PROCESS_ALL_ACCESS to processes with uncommon target image filenames.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_accessLow444Free2024-05-27Windows PowerShell ScriptBlock Adds Allow Firewall Rule via New-NetFirewallRule
Flags PowerShell ScriptBlock text that invokes New-NetFirewallRule to add an Allow firewall rule.
frack113, Huntrule TeamWindowsps_scriptLow110Free2024-05-10Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes
Alerts when unusual processes access Outlook Unistore (data and UnistoreDB store.vol) file locations on Windows.
frack113, Huntrule TeamWindowsfile_accessLow110Free2024-05-10PowerShell New-NetFirewallRule Adds Windows Allow Firewall Rule
Alert on PowerShell creating a new Windows firewall rule that sets the action to Allow via New-NetFirewallRule.
frack113, Huntrule TeamWindowsprocess_creationLow90Free2024-05-03Kubernetes API Audit: Unauthorized (401) or Forbidden (403) Access Attempts
Alerts on Kubernetes API audit events returning 401 or 403, indicating authentication or authorization failures.
kelnage, Huntrule TeamKubernetesauditLow482Free2024-04-12Kubernetes Service Account Created via Audit Log
Alerts on Kubernetes audit events showing new ServiceAccounts created.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow451Free2024-03-26Kubernetes Audit: Listing Secrets (Enumeration of Secret Resources)
Alerts on Kubernetes audit requests that list the secrets resource, consistent with secret enumeration.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow133Free2024-03-26Kubernetes RBAC SelfSubjectRulesReview Permission Enumeration Attempt
Alerts on Kubernetes selfsubjectrulesreviews API calls that enumerate the caller’s RBAC permissions.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow122Free2024-03-26