Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
OpenSSH Server (sshd) Listening on SSH Socket on Windows
Flags OpenSSH (sshd) events showing the SSH server has started listening on a socket.
mdecrevoisier, Huntrule TeamWindowsopensshMedium123Free2022-10-25Inveigh Execution via Process Creation (Windows)
Detects execution of Inveigh.exe on Windows with spoofing/sniffing command-line flags consistent with MITM behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical305Free2022-10-24PowerShell: Suspicious Set-Service DACL/SecurityDescriptor Modification for Hidden Services
Flags PowerShell ScriptBlock activity using Set-Service with specific SDDL elements consistent with hiding services from tools like sc.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh82Free2022-10-24Windows Inveigh HackTool Execution Artefacts via Inveigh File Indicators
Alert on Windows file creation or presence of Inveigh log, script, and binary artefacts identified by distinctive filename suffixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical427Free2022-10-24Windows MsiInstaller installs remote MSI from web URLs (EventID 1040/1042)
Flags Windows Installer MsiInstaller events that indicate downloading and installing an MSI from a URL.
Stamatis Chatzimangou, Huntrule TeamWindowsapplicationMedium112Free2022-10-23Windows Alternate Data Stream Creation: Suspicious Zone.Identifier ADS Outside Browser Download
Flags suspicious creation of :Zone.Identifier ADS streams (ZoneTransfer/ZoneId=3) on file types outside typical browsers.
frack113, Huntrule TeamWindowscreate_stream_hashMedium121Free2022-10-22Windows: Suspicious Child Processes Spawned by Electron Apps
Flags suspicious command/scripting child processes launched by Electron apps such as Teams, Discord, Slack, and Edge.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium347Free2022-10-21Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Alerts when onenote.exe spawns suspicious script or system execution child processes on Windows, consistent with malicious OneNote payload behavior.
Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh60Free2022-10-21Windows DLL Search Order Hijacking: Suspicious DLL Writes to App Dependency Folders
Alerts on suspicious .dll file creation by Office/cmd/scripting processes in AppData and OneDrive/Teams/Slack/VS Code directories.
Tim Rauch (rule), Elastic (idea), Huntrule TeamWindowsfile_eventMedium143Free2022-10-21macOS Script Editor Spawns Suspicious Command-Line Interpreters
Alerts when Script Editor launches command-line tools or interpreters like curl, shell binaries, python, or perl.
Tim Rauch (rule), Elastic (idea), Huntrule TeamMacosprocess_creationMedium162Free2022-10-21Windows Process Execution: SafetyKatz HackTool (SafetyKatz.exe)
Alerts when a process running SafetyKatz.exe is created, using image path and embedded file metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2022-10-20Windows Process Creation: Seatbelt.exe PUA Discovery Command-Line Execution
Alerts on Windows process launches of Seatbelt.exe with discovery group arguments and outputfile usage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh202Free2022-10-18PowerShell Set-Acl targeting Windows folder paths on Windows
Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-10-18PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
Detects PowerShell Set-Service commands with SecurityDescriptorSddl SDDL patterns that modify Windows service DACLs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh373Free2022-10-18