Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows DNS Client: MEGA userstorage subdomain DNS query (EventID 3008)
Detects Windows DNS client queries for MEGA userstorage subdomains by matching the query name string.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientMedium122Free2023-01-16Windows DNS Client: Cobalt Strike DNS Beaconing Patterns via Suspicious Query Names
Alerts when Windows DNS client logs show Event ID 3008 DNS queries matching Cobalt Strike beacon patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientCritical4410Free2023-01-16Windows DNS Client: DNS query for anonfiles.com domain
Alerts when Windows DNS client logs show a DNS query containing .anonfiles.com.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientHigh161Free2023-01-16Windows AppX Packaging: Execute AppX with Suspicious Digital Signature Certificate
Alerts when AppX package execution/signature subject matches a known suspicious certificate in Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxpackaging-omMedium112Free2023-01-16Windows AppX Execution of Sysinternals Tools (procdump/psloglist/psexec/livekd/ADExplorer)
Flags execution of common Sysinternals binaries when launched through the Windows AppX runtime.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappmodel-runtimeLow316Free2023-01-16Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
Flags registry writes that reference an Excel XLL add-in via a '/R ' command under Excel Options.
frack113, Huntrule TeamWindowsregistry_setHigh378Free2023-01-15Windows Registry: DisableRestrictedAdmin Value Tampering to Change Restricted Admin Mode
Flags registry modifications to DisableRestrictedAdmin that change Restricted Admin mode settings.
frack113, Huntrule TeamWindowsregistry_setHigh112Free2023-01-13Windows Process Creation: Registry Tampering of DisableRestrictedAdmin in Lsa Key
Alerts when a process command line references LSA DisableRestrictedAdmin to change RestrictedAdmin behavior via the registry.
frack113, Huntrule TeamWindowsprocess_creationHigh417Free2023-01-13Windows Task Scheduler: Detects Scheduled Task Deletion or Disabling (Task Deleted/Disabled)
Alert on deletion or disabling of targeted Windows scheduled tasks tied to system, security, and update components.
frack113, Huntrule TeamWindowstaskschedulerHigh244Free2023-01-13Windows LSA event: Standard user SID in privileged AD groups (EventID 300)
Alerts when LSA Event 300 shows a standard user interacting with high-privileged group SIDs, excluding common domain admin patterns.
frack113, Huntrule TeamWindowslsa-serverMedium142Free2023-01-13Windows Registry change enabling developer features for sideloading and untrusted app installs
Alerts on registry writes that enable Windows developer feature policies allowing sideloading of untrusted apps.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2023-01-12Windows process creation: Suspicious child processes from WindowsApps directory
Alerts on suspicious cmd/PowerShell/mshta/rundll32-style child processes launched from Program Files\WindowsApps.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2023-01-12Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)
Flags Windows SRP enforcement events where attempts to access applications are restricted by administrator policy.
frack113, Huntrule TeamWindowsapplicationHigh447Free2023-01-12Linux mount executed with hidepid=2 option
Flags Linux mounts that include hidepid=2, a stealth configuration that hides processes from other users.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationMedium153Free2023-01-12Windows Registry PowerShell ExecutionPolicy Tampering (Bypass/Unrestricted)
Alerts on Windows registry changes that set PowerShell ExecutionPolicy to Bypass or Unrestricted.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium382Free2023-01-11