Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Huawei BGP Authentication Failures Indicating Failed Session Attempts
Flags Huawei BGP authentication failure log events that may indicate credential attempts or routing manipulation.
Tim Brown, Huntrule TeamHuaweibgpLow246Free2023-01-09Cisco LDP MD5 Authentication Failure Events
Flags Cisco LDP TCP MD5 authentication failure events that may indicate brute-force attempts to affect MPLS label signaling.
Tim Brown, Huntrule TeamCiscoldpLow82Free2023-01-09Cisco BGP Authentication Failure Events Indicating Potential Credential Attacks
Flags Cisco BGP authentication failure events associated with TCP/179 traffic that may indicate credential abuse.
Tim Brown, Huntrule TeamCiscobgpLow268Free2023-01-09Windows PowerShell Script Block Alerts for Set-Alias and New-Alias Usage
Alerts on PowerShell scripts that create aliases via Set-Alias/New-Alias, a common obfuscation technique, using ScriptBlockText logging.
frack113, Huntrule TeamWindowsps_scriptLow485Free2023-01-08Windows Suspicious Double-Extension Execution via Parent Command Line
Alerts on Windows processes launched by parents whose image/command line includes disguised double-extension tokens.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh169Free2023-01-06AWS CloudTrail: Potential S3 Bucket Enumeration via ListBuckets by Non-AssumedRole
Identifies S3 ListBuckets calls in CloudTrail that are not from assumed-role identities, which may indicate bucket discovery activity.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamAwscloudtrailLow142Free2023-01-06Windows PowerShell Process Creation: Suspicious Base64/Encoded and IEX WebClient Patterns
Detects suspicious PowerShell process command lines using hidden/no-profile, execution-policy bypass, and encoded/Base64 or IEX WebClient download patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-01-05Windows PowerShell: ScriptBlock using security descriptor (Win32_Trustee/Win32_Ace) and LSA data strings
Alerts on PowerShell ScriptBlock text that manipulates security descriptors and LSA-related identifiers, indicating possible persistence behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh352Free2023-01-05Windows Registry AMSI COM Server Hijacking via InProcServer32 CLSID Modification
Alerts on registry changes that alter an AMSI COM CLSID InProcServer32 entry to break AMSI loading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh428Free2023-01-04Windows PowerShell Keylogger Function Reference in Script Block Logging
Alerts on PowerShell script blocks containing keyboard IsKeyDown references associated with potential keystroke capture.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium111Free2023-01-04Windows Process Creation: Suspicious Git Clone Command With Vulnerability Keywords
Flags Windows git clone commands that include exploit/vulnerability-style keywords in the process command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium469Free2023-01-03Linux process execution matches known hacktools by image name
Alerts on Linux process executions of known hacktool, scanner, web enumeration, and exploit utility binaries by image name.
Nasreddine Bencherchali (Nextron Systems), Georg Lauenstein (sure[secure]), Huntrule TeamLinuxprocess_creationHigh403Free2023-01-03Linux Process Creation: Suspicious Git Clone Command with Vulnerability Keywords
Alerts on Linux "git clone" commands that include exploit/vulnerability-related keywords or CVE/PoC-style terms.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium444Free2023-01-03Linux Package Installation via apt/yum/rpm/dpkg with Networking Tools Keywords
Alerts when apt/yum/rpm/dpkg install commands include reconnaissance or proxy tool keywords.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium488Free2023-01-03Windows Registry EventLog Service File Location Tampering
Flags registry modifications that change the EventLog service’s configured log file location on Windows.
D3F7A5105, Huntrule TeamWindowsregistry_setHigh161Free2023-01-02