Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows process activity enabling Developer Mode or sideloading via SystemSettingsAdminFlows.exe
Alerts on SystemSettingsAdminFlows.exe command lines enabling Developer Mode unlock or application sideloading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-01-11Windows Process Creation: PowerShell Execution Policy Registry Tampering via CommandLine
Alerts when a process command line references PowerShell ExecutionPolicy registry paths and weaker policy values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2023-01-11Windows BITS Client Job Downloads from Direct IP Addresses
Alerts when Windows BITS Client downloads via HTTP/HTTPS URLs containing direct IP addresses.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsbits-clientHigh352Free2023-01-11Windows AppX Deployment: Uncommon Appx Path Added to Deployment Pipeline
Alerts when an AppX package is queued for processing from uncommon paths or URLs in Windows AppX deployment server events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium101Free2023-01-11Windows AppX Deployment Blocked by Local Policy
Detects blocked AppX package deployments on Windows via AppXDeployment-Server policy-denial Event IDs.
frack113, Huntrule TeamWindowsappxdeployment-serverMedium153Free2023-01-11Windows AppX Package Deployment: Suspicious AppX Installation Attempts by PackageFullName
Alerts on Windows AppX deployment events tied to a known-malicious AppX package identifier.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium162Free2023-01-11Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh101Free2023-01-11Windows AppX Deployment Failure (0x80073cff) Due to Signing Requirements
Alerts on Windows AppX deployments/installations failing with 0x80073cff, consistent with unmet signing requirements.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium162Free2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh426Free2023-01-11Windows AppX deployment blocked by AppLocker (AppXDeployment-Server EventID 412)
Flags AppX package deployment attempts that AppLocker blocked, based on AppXDeployment-Server EventID 412.
frack113, Huntrule TeamWindowsappxdeployment-serverMedium273Free2023-01-11Linux Service File Touch with Timestamp Argument
Alerts when touch is executed with a timestamp flag on a .service file, indicating potential stealthy service manipulation.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationMedium142Free2023-01-11Windows Process Creation: PowerShell Import-Module from Temp/AppData/Public Paths
Alerts on PowerShell Import-Module calls that load modules from Temp, AppData, or Public directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium406Free2023-01-10Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh90Free2023-01-10PowerShell script alias obfuscation via -Value (-join(...))
Flags PowerShell script blocks that set aliases using -Value with a (-join(...)) character-joining obfuscation pattern.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow417Free2023-01-09Juniper BGP Logs: Missing MD5 Digest in Route Authentication
Flags Juniper BGP log messages indicating a missing MD5 digest, highlighting potential exposure from unauthenticated routing sessions.
Tim Brown, Huntrule TeamJuniperbgpLow91Free2023-01-09