Skip to content

Releases: SigmaHQ/sigma

Release r2026-07-01

Choose a tag to compare

@github-actions github-actions released this 09 Jul 14:51
552f3fe

New Rules

  • new: Antivirus - APT Malware Signature
  • new: Antivirus - Remote Access Tools Signature
  • new: AppLocker Application Would Have Been Blocked
  • new: Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator
  • new: Curl File Upload To File Sharing Websites
  • new: Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
  • new: LSASS Crash Via Netlogon Stack Buffer Overflow - CVE-2026-41089
  • new: Linux AF_ALG Socket Creation - Kernel Crypto API Exploit Indicator
  • new: NTLM Hash Leak Via Curl NTLM Authentication
  • new: New Agent Skills Installation Attempt Via Node.EXE
  • new: Process Execution from Shared Memory Directory
  • new: RedTail Cryptominer User-Agent
  • new: Registry Enumeration via WMI Stdregprov
  • new: Signed DLL Loaded With Missing PE Version Metadata
  • new: TanStack Supply-Chain Attack DNS Indicators
  • new: TanStack Supply-Chain Attack Execution Indicators - Linux
  • new: TanStack Supply-Chain Attack Execution Indicators - Windows
  • new: TanStack Supply-Chain Attack File Creation Indicators - Linux
  • new: TanStack Supply-Chain Attack File Creation Indicators - Windows
  • new: Windows Defender Disabled Via SystemSettingsAdminFlows.EXE

Updated Rules

  • update: 7Zip Compressing Dump Files - Add missing 7zr.exe OriginalFileName entries
  • update: Amsi.DLL Load By Uncommon Process - add ARM64 (*64a.exe) variant
  • update: Antivirus - Exploitation Framework Signature - add multiple new strings
  • update: Antivirus - Hacktool Signature - add multiple new strings
  • update: Antivirus - Password Dumper Signature - add multiple new strings
  • update: Antivirus - Ransomware Signature - add multiple new strings
  • update: Antivirus - Relevant File Paths Alerts Signature - change to new style title
  • update: Antivirus - Web Shell Detection Signature - change to new style title
  • update: Application Termination Attempt Via Wmic.EXE - rename, expand description
  • update: BITS Transfer Job Download From File Sharing Domains - add more file sharing domains
  • update: Compress Data and Lock With Password for Exfiltration With 7-ZIP - Add missing 7zr.exe OriginalFileName entries
  • update: CredUI.DLL Loaded By Uncommon Process - add ARM64 (*64a.exe) variant
  • update: HackTool - SysmonEnte Execution - add ARM64 (*64a.exe) variant
  • update: Legitimate Application Dropped Executable - add .pyc, .jar extensions
  • update: Legitimate Application Dropped Script - add various scripts extensions
  • update: Local System Accounts Discovery - MacOs - Re-work logic to enhance coverage and fix incorrect assumptions
  • update: Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder - add more file sharing domains
  • update: Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location - add more file sharing domains
  • update: New Connection Initiated To Potential Dead Drop Resolver Domain - add more file sharing domains
  • update: NewActiveScriptEventConsumer Creation Attempt Via Wmic.EXE - rename, expand description, add OriginalFileName to detection
  • update: Password Protected Compressed File Extraction Via 7Zip - Add missing 7zr.exe OriginalFileName entries
  • update: Permission Check Via Accesschk.EXE - add ARM64 (*64a.exe) variant
  • update: Potential Credential Dumping Activity Via LSASS - add ARM64 (*64a.exe) variant
  • update: Potential Defense Evasion Via Binary Rename - Add missing 7zr.exe OriginalFileName entries
  • update: Potential Defense Evasion Via Rename Of Highly Relevant Binaries - add ARM64 (*64a.exe) variant
  • update: Potential Privileged System Service Operation - SeLoadDriverPrivilege - add ARM64 (*64a.exe) variant
  • update: Potential Process Reconnaissance Via Wmic.EXE - rename, expand description, add discovery tags, add terminate filter
  • update: Potential WinAPI Calls Via PowerShell Scripts - add local shellcode injection patterns
  • update: Potentially Suspicious AccessMask Requested From LSASS - add ARM64 (*64a.exe) variant
  • update: Potentially Suspicious File Download From File Sharing Domain Via PowerShell.EXE - add more file sharing domains
  • update: Potentially Suspicious GrantedAccess Flags On LSASS - add ARM64 (*64a.exe) variant
  • update: Procdump Execution - add ARM64 (*64a.exe) variant
  • update: Process Creation Attempt Via Wmic.EXE - rename, expand description
  • update: Process Explorer Driver Creation By Non-Sysinternals Binary - add ARM64 (*64a.exe) variant
  • update: Process Monitor Driver Creation By Non-Sysinternals Binary - add ARM64 (*64a.exe) variant
  • update: Registry Manipulation via WMI Stdregprov - expand description, scope detection to write methods, add related reference
  • update: Renamed ProcDump Execution - add ARM64 (*64a.exe) variant
  • update: Renamed Sysinternals Sdelete Execution - add ARM64 (*64a.exe) variant
  • update: Suspicious Download From File-Sharing Website Via Bitsadmin - add more file sharing domains
  • update: Suspicious Execution Of Renamed Sysinternals Tools - Registry - add ARM64 (*64a.exe) variant
  • update: Suspicious File Download From File Sharing Domain Via Curl.EXE - add more file sharing domains
  • update: Suspicious File Download From File Sharing Domain Via Wget.EXE - add more file sharing domains
  • update: Suspicious File Download From File Sharing Websites - File Stream - add more file sharing domains
  • update: Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE - add more file sharing domains
  • update: Suspicious PROCEXP152.sys File Created In TMP - add ARM64 (*64a.exe) variant
  • update: Suspicious Remote AppX Package Locations - add more file sharing domains
  • update: Suspicious Service Installed - add ARM64 (*64a.exe) variant
  • update: Suspicious Start-Process PassThru - Added the alias saps for increased coverage
  • update: Suspicious Use of PsLogList - add ARM64 (*64a.exe) variant
  • update: Suspicious User-Agents Related To Recon Tools - add additional default user-agents for multiple recon utilities
  • update: Sysinternals PsService Execution - add ARM64 (*64a.exe) variant
  • update: Sysinternals PsSuspend Execution - add ARM64 (*64a.exe) variant
  • update: Sysinternals PsSuspend Suspicious Execution - add ARM64 (*64a.exe) variant
  • update: Sysmon Configuration Update - add ARM64 (*64a.exe) variant
  • update: System File Execution Location Anomaly - add wmic.exe for increased coverage
  • update: Uninstall Sysinternals Sysmon - add ARM64 (*64a.exe) variant
  • update: Unusual File Download From File Sharing Websites - File Stream - add more file sharing domains
  • update: Usage of Renamed Sysinternals Tools - RegistrySet - add ARM64 (*64a.exe) variant
  • update: Vim GTFOBin Abuse - Linux - Increase coverage and enhance logic
  • update: WMI Module Loaded By Uncommon Process - add ARM64 (*64a.exe) variant
  • update: WMI Persistence - Script Event Consumer - expand description, add reference

Fixed Rules

  • fix: Azure Application Deleted - add refs and align fields to Event Hub format
  • fix: Azure Device No Longer Managed or Compliant - add refs and align fields to Event Hub format
  • fix: Azure Owner Removed From Application or Service Principal - add refs and align fields to Event Hub format
  • fix: Azure Service Principal Created - add refs and align fields to Event Hub format
  • fix: Azure Service Principal Removed - add refs and align fields to Event Hub format
  • fix: Clipboard Access Via OSAScript - Filter OpenCode and update metadata
  • fix: Cmd.EXE Missing Space Characters Execution Anomaly - add filter for empty cmd /c argument
  • fix: CobaltStrike Named Pipe Pattern Regex - Tightened regular expression
  • fix: Creation of WerFault.exe/Wer.dll in Unusual Folder - filter wualtcore
  • fix: Disabled MFA to Bypass Authentication Mechanisms - add refs and align fields to Event Hub format
  • fix: Execution Of Non-Existing File - add vmmemWSL exception
  • fix: File And SubFolder Enumeration Via Dir Command - fix mismatch with rmdir
  • fix: MacOS Scripting Interpreter AppleScript - Add filter for OpenCode
  • fix: Potential Product Reconnaissance Via Wmic.EXE - filter csproduct
  • fix: Potential Vcruntime140 DLL Sideloading - filter OneDrive
  • fix: Potentially Suspicious WDAC Policy File Creation - filter new path of wuaucltcore
  • fix: Process Reconnaissance Via Wmic.EXE- filter usage of 'call terminate'
  • fix: Service Reconnaissance Via Wmic.EXE - filter stopservice and startservice
  • fix: Suspicious Eventlog Clearing or Configuration Change Activity - Fix parentheses in condition
  • fix: Suspicious Volume Shadow Copy Vssapi.dll Load - filter winre path
  • fix: UFW Disable Attempt - Fix broken ufw-init detection and broaden UFW disable coverage
  • fix: User Added to an Administrator's Azure AD Role - add refs and align fields to Event Hub format

Acknowledgement

Thanks to @ahu-exeon, @AJ-Jeffreys, @CHIRAG-DAMANI-08, @eeee2345, @einlamye, @eriknordstrm, @EzLucky, @frack113, @fukusuket, @gkazimiarovich, @heyyanu, @kurisukun, @leogasparini, @marcopedrinazzi, @munzzyy, @nasbench, @Neo23x0, @norbert791, @Nullbyte0x, @PachkaKofe04, @phantinuss, @potato-20, @ruppde, @srkyn, @stanlee786, @swachchhanda000, @uniqu3-us3r, @vl43den, @X-Junior, @ywahl, @zendannyy for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2026-04-01

Choose a tag to compare

@github-actions github-actions released this 28 Apr 11:32
0e3b749

New Rules

  • new: Axios NPM Compromise File Creation Indicators - Linux
  • new: Axios NPM Compromise File Creation Indicators - MacOS
  • new: Axios NPM Compromise File Creation Indicators - Windows
  • new: Axios NPM Compromise Indicators - Linux
  • new: Axios NPM Compromise Indicators - MacOS
  • new: Axios NPM Compromise Indicators - Windows
  • new: Axios NPM Compromise Malicious C2 Domain DNS Query
  • new: Azure Sign-In With Axios User Agent
  • new: Cisco Dot1x Disabled
  • new: DMSA Link Attributes Modified
  • new: DMSA Service Account Created in Specific OUs - PowerShell
  • new: Google Workspace Government Attack Warning
  • new: Google Workspace Out Of Domain Email Forwarding
  • new: HackTool - NetExec File Indicators
  • new: Hacktool - NetExec Execution
  • new: Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet
  • new: Inbox Rules Creation Or Update Activity in O365
  • new: Indirect Command Execution via SFTP ProxyCommand
  • new: Kubernetes Potential Enumeration Activity
  • new: LiteLLM / TeamPCP Supply Chain Attack Indicators
  • new: Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet
  • new: New DMSA Service Account Created in Specific OUs
  • new: New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created
  • new: Notepad++ Updater DNS Query to Uncommon Domains
  • new: Okta Session Impersonation Granted From Untrusted Domain
  • new: OpenEDR Spawning Command Shell
  • new: PUA - Memory Dump Mount Via MemProcFS
  • new: Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI
  • new: Potential Exploitation of CVE-2025-5054 or CVE-2025-4598
  • new: Potential Vcruntime140 DLL Sideloading
  • new: Potentially Suspicious File Creation by OpenEDR's ITSMService
  • new: Python Base64 Encoded Inline Command Execution - Linux
  • new: Python Base64 Encoded Inline Command Execution - Windows
  • new: RedSun - Conhost.exe Spawned by TieringEngineService.exe
  • new: RedSun - Named Pipe Created
  • new: RedSun - TieringEngineService.exe Detected as EICAR Test File
  • new: RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir
  • new: Script Interpreter Spawning Credential Scanner - Linux
  • new: Script Interpreter Spawning Credential Scanner - Windows
  • new: Sensitive File Dump Via Print.EXE
  • new: Service Startup Type Change Via Wmic.EXE
  • new: Shai-Hulud 2.0 Malicious NPM Package Installation
  • new: Shai-Hulud 2.0 Malicious NPM Package Installation - Linux
  • new: Shai-Hulud Malicious Bun Execution
  • new: Shai-Hulud Malicious Bun Execution - Linux
  • new: Shai-Hulud Malware Indicators - Linux
  • new: Shai-Hulud Malware Indicators - Windows
  • new: Suspicious Child Process of Notepad++ Updater - GUP.Exe
  • new: Suspicious Child Process of SolarWinds WebHelpDesk
  • new: Suspicious Email Delivered In Microsoft 365
  • new: Suspicious Login Activity Classified By Google
  • new: System Language Discovery via Reg.Exe
  • new: System Restore Registry Modification via CommandLine
  • new: TeamPCP LiteLLM Supply Chain Attack Persistence Indicators
  • new: Uncommon File Created by Notepad++ Updater Gup.EXE
  • new: Windows EventLog Autologger Session Registry Modification Via CommandLine
  • new: msDS-ManagedAccountPrecededByLink Attribute Modified

Updated Rules

  • update: BPFDoor Abnormal Process ID or Lock File Accessed - add new file paths from Rapid7 research to increase coverage
  • update: Csc.EXE Execution Form Potentially Suspicious Parent - Update regex to use a non-capturing group
  • update: Delete Important Scheduled Task - Add OFN and remove unecessary string binding for increased coverage.
  • update: Disable Important Scheduled Task - Add OFN and remove unecessary string binding for increased coverage.
  • update: Dynamic .NET Compilation Via Csc.EXE - Update regex to use a non-capturing group
  • update: Files With System Process Name In Unsuspected Locations - Add fsquirt.exe entry
  • update: Github Delete Action Invoked - Rename action from 'codespaces.delete' to 'codespaces.destroy'
  • update: Important Scheduled Task Deleted or Disabled - Add EventID 142.
  • update: Invoke-Obfuscation Obfuscated IEX Invocation - Update regex to use a non-capturing group
  • update: Invoke-Obfuscation Via Stdin - Update regex to use a non-capturing group
  • update: Invoke-Obfuscation Via Use Clip - Update regex to use a non-capturing group
  • update: LSA PPL Protection Setting Modification via CommandLine - Add more keys regarding LSA PPL
  • update: New Cron File Created - Enhance coverage and update metadata
  • update: New Okta User Created - Update field name to use CamleCase
  • update: Obfuscated IP Download Activity - Update regex to use a non-capturing group
  • update: Obfuscated IP Via CLI - Update regex to use a non-capturing group
  • update: Okta 2023 Breach Indicator Of Compromise - Update field name to use CamleCase
  • update: Okta API Token Created - Update field name to use CamleCase
  • update: Okta API Token Revoked - Update field name to use CamleCase
  • update: Okta Admin Role Assigned to an User or Group - Update field name to use CamleCase
  • update: Okta Admin Role Assignment Created - Update field name to use CamleCase
  • update: Okta Application Modified or Deleted - Update field name to use CamleCase
  • update: Okta Application Sign-On Policy Modified or Deleted - Update field name to use CamleCase
  • update: Okta FastPass Phishing Detection - Update field name to use CamleCase
  • update: Okta Identity Provider Created - Update field name to use CamleCase
  • update: Okta MFA Reset or Deactivated - Update field name to use CamleCase
  • update: Okta Network Zone Deactivated or Deleted - Update field name to use CamleCase
  • update: Okta New Admin Console Behaviours - Update field name to use CamleCase
  • update: Okta Policy Modified or Deleted - Update field name to use CamleCase
  • update: Okta Policy Rule Modified or Deleted - Update field name to use CamleCase
  • update: Okta Security Threat Detected - Update field name to use CamleCase
  • update: Okta Suspicious Activity Reported by End-user - Update field name to use CamleCase
  • update: Okta Unauthorized Access to App - Update field name to use CamleCase
  • update: Okta User Account Locked Out - Update field name to use CamleCase
  • update: Okta User Session Start Via An Anonymising Proxy Service - Update field name to use CamleCase
  • update: Potential AutoLogger Sessions Tampering - Update the value to an accurate one
  • update: Potential Defense Evasion Via Rename Of Highly Relevant Binaries - add finger.exe
  • update: Potential Defense Evasion Via Right-to-Left Override - Add real rtlo char copied/pasted
  • update: Potential Dropper Script Execution Via WScript/CScript/MSHTA - Add additional file path and extension for coverage and enhance metadata
  • update: Potential File Extension Spoofing Using Right-to-Left Override - Add real rtlo char copied/pasted
  • update: Potential Okta Password in AlternateID Field - Update field name to use CamleCase
  • update: Potential Rundll32 Execution With DLL Stored In ADS - Update regex to use a non-capturing group
  • update: Potentially Suspicious Powershell Script Execution From Temp Folder - Reduce level to medium and enhance metadata
  • update: PowerShell Download Via Net.WebClient - PowerShell Classic - Reduce level to "low" and update metadata
  • update: Powershell Token Obfuscation - Process Creation - Update regex to use a non-capturing group
  • update: Script Interpreter Execution From Suspicious Folder - Add additional file path for coverage and enhance metadata
  • update: Service Reconnaissance Via Wmic.EXE - Add filters to exclude out legitimate service manipulation cases.
  • update: Shai-Hulud Malicious GitHub Workflow Creation - Add new entries to the list to increase coverage
  • update: Shell Invocation via Env Command - Linux - Switch modifier to use contains instead of endswith for better accuracy
  • update: Suspicious Copy From or To System Directory - Update regex to use a non-capturing group
  • update: Suspicious Creation TXT File in User Desktop - Move to a TH rule
  • update: System Control Panel Item Loaded From Uncommon Location - Add entries for bthprops.cpl and hdwwiz.cpl
  • update: System File Execution Location Anomaly - Add fsquirt.exe entry
  • update: System File Execution Location Anomaly - add finger.exe
  • update: Uncommon Svchost Command Line Parameter - Update regex to use a non-capturing group
  • update: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript - Add entry for .wsh files
  • update: WScript or CScript Dropper - File - Enhance coverage with multiple file paths and extesnions
  • update: WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze - change it into hunting rule

Removed / Deprecated Rules

  • remove: Suspicious PowerShell Mailbox SMTP Forward Rule

Fixed Rules

  • fix: BITS Transfer Job With Uncommon Or Suspicious Remote TLD - Add filter entry for "tscdn.m365.static.microsoft"
  • fix: BloodHound Collection Files - Remove entry _domains.json due to FP rate.
  • fix: Chmod Targeting Sensitive Directories - enhance metadata and add multipel filters for legit use cases
  • fix: CodeIntegrity - Unmet Signing Level Requirements By File Under Validation - Add filter entry for MS office path
  • fix: Disable Or Stop Services - Add new filters for legitimate service stoppoing via systemctl for snapd, asw and others
  • fix: HackTool - WSASS Execution - update regex to avoid mismatching on legitimate cli
  • fix: Linux Logs Clearing Attempts - Add new filters for sysstat and dmesg legitimate command deletion
  • fix: Non Interactive PowerShell Process Spawned - Add filter entry for "SenseIR.exe"
  • fix: Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation - Add additional path for nsswitch /usr/share/factory/etc/nsswitch.conf
  • fix: Notepad++ ...
Read more

Release r2026-01-01

Choose a tag to compare

@github-actions github-actions released this 29 Jan 12:57
478120e

New Rules

  • new: AMSI Disabled via Registry Modification
  • new: Cmd Launched with Hidden Start Flags to Suspicious Targets
  • new: Devcon Execution Disabling VMware VMCI Device
  • new: Github Self-Hosted Runner Execution
  • new: HTML File Opened From Download Folder
  • new: Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
  • new: Legitimate Application Writing Files In Uncommon Location
  • new: Linux Setgid Capability Set on a Binary via Setcap Utility
  • new: Linux Setuid Capability Set on a Binary via Setcap Utility
  • new: Linux Suspicious Child Process From Node.js - React2Shell
  • new: OpenCanary - Host Port Scan (SYN Scan)
  • new: OpenCanary - NMAP FIN Scan
  • new: OpenCanary - NMAP NULL Scan
  • new: OpenCanary - NMAP OS Scan
  • new: OpenCanary - NMAP XMAS Scan
  • new: OpenCanary - RDP New Connection Attempt
  • new: PUA - Kernel Driver Utility (KDU) Execution
  • new: Registry Modification for OCI DLL Redirection
  • new: Successful MSIX/AppX Package Installation
  • new: Suspicious ArcSOC.exe Child Process
  • new: Suspicious File Created by ArcSOC.exe
  • new: Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
  • new: Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
  • new: Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
  • new: Suspicious Shell Open Command Registry Modification
  • new: User Shell Folders Registry Modification via CommandLine
  • new: Vulnerable Driver Blocklist Registry Tampering Via CommandLine
  • new: WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze
  • new: Windows AMSI Related Registry Tampering Via CommandLine
  • new: Windows AppX Deployment Full Trust Package Installation
  • new: Windows AppX Deployment Unsigned Package Installation
  • new: Windows Credential Guard Disabled - Registry
  • new: Windows Credential Guard Registry Tampering Via CommandLine
  • new: Windows Credential Guard Related Registry Value Deleted - Registry
  • new: Windows MSIX Package Support Framework AI_STUBS Execution
  • new: Windows Suspicious Child Process From Node.js - React2Shell
  • new: Windows Vulnerable Driver Blocklist Disabled

Updated Rules

  • update: ASLR Disabled Via Sysctl or Direct Syscall - Linux - Updated syscall field to SYSCALL in order to make use of enriched logs
  • update: AppX Located in Uncommon Directory Added to Deployment Pipeline - Enhance selection criteria
  • update: Audio Capture - Updated syscall field to SYSCALL in order to make use of enriched logs
  • update: BITS Transfer Job Download From File Sharing Domains - add github.com
  • update: Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
  • update: Creation Of Non-Existent System DLL - Add new DLLs and update metadata
  • update: Curl Web Request With Potential Custom User-Agent - add another curl supported flag for header
  • update: DNS Query to External Service Interaction Domains - Changed modifier to endswith for better accuracy and add additional domains.
  • update: Direct Autorun Keys Modification - remove User Shell Folder registry modification
  • update: File Download Via Bitsadmin To A Suspicious Target Folder - add more susp locations
  • update: Hacktool - EDR-Freeze Execution - add more coverage
  • update: Malicious PowerShell Commandlets - PoshModule - add Invoke-DNSExfiltrator
  • update: Malicious PowerShell Commandlets - ProcessCreation - add Invoke-DNSExfiltrator
  • update: Malicious PowerShell Commandlets - ScriptBlock - add Invoke-DNSExfiltrator
  • update: Malicious PowerShell Scripts - FileCreation - add Invoke-DNSExfiltrator
  • update: Malicious PowerShell Scripts - PoshModule - add Invoke-DNSExfiltrator
  • update: Modify User Shell Folders Startup Value - add new registry path, also add filtering of legit paths
  • update: Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder - add github.com
  • update: Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location - add github.com
  • update: Potential DLL Sideloading Of Non-Existent DLLs From System Folders - Add new DLLs and update metadata
  • update: Potential Malicious Usage of CloudTrail System Manager - Update logic to use errorCode instead for better mapping and accuracy
  • update: Potential SquiblyTwo Technique Execution - Extend coverage for remote execution
  • update: Potentially Suspicious EventLog Recon Activity Using Log Query Utilities - add more interesting event ids
  • update: Registry Modification of MS-settings Protocol Handler - Update logic to be more clear
  • update: Renamed Office Binary Execution - add olk.exe matching on Microsoft Outlook
  • update: Special File Creation via Mknod Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
  • update: Suspicious Download From File-Sharing Website Via Bitsadmin - add github URL
  • update: Suspicious Download Via Certutil.EXE - add URL flag related with GUI-based download
  • update: Suspicious File Download From File Sharing Domain Via Curl.EXE - add github.com
  • update: Suspicious File Download From File Sharing Domain Via Wget.EXE - add github.com
  • update: Suspicious File Download From File Sharing Websites - File Stream - add github.com
  • update: Suspicious File Downloaded From Direct IP Via Certutil.EXE - add URL flag related with GUI-based download
  • update: Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE - add URL flag related with GUI-based download and github domain
  • update: Suspicious Package Installed - Linux - add 'socat' keyword and fix a typo
  • update: Suspicious Remote AppX Package Locations - add github.com
  • update: System Info Discovery via Sysinfo Syscall - Updated syscall field to SYSCALL in order to make use of enriched logs
  • update: Unusual File Download From File Sharing Websites - File Stream - add github.com
  • update: WMIC Loading Scripting Libraries - Update metadata
  • update: Webshell Remote Command Execution - Updated syscall field to SYSCALL in order to make use of enriched logs
  • update: XSL Script Execution Via WMIC.EXE - Filter out remote execution parameters to avoid duplicate alerting

Removed / Deprecated Rules

  • remove: File Download Via Bitsadmin To An Uncommon Target Folder - deprecate in favor of 2ddef153-167b-4e89-86b6-757a9e65dcac

Fixed Rules

  • fix: Capabilities Discovery - Linux - Removed unnecessary windash modifier
  • fix: Creation of WerFault.exe/Wer.dll in Unusual Folder - filter C:\Windows\UUS\arm64\
  • fix: CredUI.DLL Loaded By Uncommon Process - filter systemapps
  • fix: Files With System Process Name In Unsuspected Locations - filter windows temp
  • fix: GUI Input Capture - macOS - remove osascript wrong path
  • fix: Load Of RstrtMgr.DLL By An Uncommon Process - filter OneDriveStandaloneUpdater.exe
  • fix: Potential Defense Evasion Via Raw Disk Access By Uncommon Tools - filter legitimate ARM based locations
  • fix: Potential System DLL Sideloading From Non System Locations - filter legitimate ARM based locations
  • fix: Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load - filter C:$WinREAgent\Scratch\
  • fix: Potentially Suspicious WDAC Policy File Creation - filter wuaucltcore.exe
  • fix: Rare Remote Thread Creation By Uncommon Source Image - filter provtool system
  • fix: Startup Folder File Write - filter out wuauclt.exe and C:$WinREAgent\Scratch\Mount\ directory
  • fix: Suspicious desktop.ini Action - filter onedrive
  • fix: Unauthorized System Time Modification - filter out vmwaretools
  • fix: Uncommon AppX Package Locations - filter out system32
  • fix: Wow6432Node CurrentVersion Autorun Keys Modification - filter null Details

Acknowledgement

Thanks to @darses, @EzLucky, @frack113, @Koifman, @marcopedrinazzi, @MATTANDERS0N, @mbabinski, @nasbench, @Niicolaa, @phantinuss, @RiqTam, @skaynum, @swachchhanda000, @toheeb-orelope, @vl43den for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2025-12-01

Choose a tag to compare

@github-actions github-actions released this 28 Nov 10:43
r2025-12-01
3565dee

New Rules

  • new: AWS GuardDuty Detector Deleted Or Updated
  • new: Atomic MacOS Stealer - FileGrabber Activity
  • new: Atomic MacOS Stealer - Persistence Indicators
  • new: Cisco ASA/FP SSL VPN Exploit (CVE-2025-20333 / CVE-2025-20362) - Proxy
  • new: DNS Query by Finger Utility
  • new: Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
  • new: Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
  • new: FortiGate - Firewall Address Object Added
  • new: FortiGate - New Administrator Account Created
  • new: FortiGate - New Firewall Policy Added
  • new: FortiGate - New Local User Created
  • new: FortiGate - New VPN SSL Web Portal Added
  • new: FortiGate - User Group Modified
  • new: FortiGate - VPN SSL Settings Modified
  • new: Grixba Malware Reconnaissance Activity
  • new: HackTool - WSASS Execution
  • new: Network Connection Initiated via Finger.EXE
  • new: Potentially Suspicious Long Filename Pattern - Linux
  • new: RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
  • new: Registry Modification Attempt Via VBScript
  • new: Registry Modification Attempt Via VBScript - PowerShell
  • new: Registry Tampering by Potentially Suspicious Processes
  • new: Renamed Schtasks Execution
  • new: Suspicious ClickFix/FileFix Execution Pattern
  • new: Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
  • new: Suspicious FileFix Execution Pattern
  • new: Suspicious Filename with Embedded Base64 Commands
  • new: Suspicious Kerberos Ticket Request via CLI
  • new: Suspicious Space Characters in RunMRU Registry Path - ClickFix
  • new: Suspicious Space Characters in TypedPaths Registry Path - FileFix
  • new: Suspicious Usage of For Loop with Recursive Directory Search in CMD
  • new: Uncommon Svchost Command Line Parameter
  • new: Unsigned .node File Loaded
  • new: Windows Default Domain GPO Modification
  • new: Windows Default Domain GPO Modification via GPME

Updated Rules

  • update: COM Object Hijacking Via Modification Of Default System CLSID Default Value - add clsid of twinapi.dll
  • update: Copy From Or To Admin Share Or Sysvol Folder - some logic change
  • update: Cred Dump Tools Dropped Files - Add procdump.exe and procdump64a.exe
  • update: DNS Query to External Service Interaction Domains - add additional domains and filters
  • update: File Download From Browser Process Via Inline URL - Enhance selection by splitting CLI markers for better matching
  • update: FileFix - Command Evidence in TypedPaths - Added more markers
  • update: JexBoss Command Sequence - Update the selection to use the |all modifier.
  • update: LOL-Binary Copied From System Directory - Add ie4uinit.exe
  • update: PPL Tampering Via WerFaultSecure - Rename and update metadata
  • update: PUA - AdFind Suspicious Execution - Add -sc to dclist string for more accurate coverage.
  • update: Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - Update selection
  • update: Potential ClickFix Execution Pattern - Registry - Add 2 new strings, "finger" and "identification"
  • update: Potential Container Discovery Via Inodes Listing - replace contains globbing with more correct patterns using regex
  • update: Potential Tampering With RDP Related Registry Keys Via Reg.EXE - Add coverage for SecurityLayer value
  • update: Potentially Suspicious NTFS Symlink Behavior Modification - Tighten logic to focus on proxy process such as cmd or powershell
  • update: RDP Sensitive Settings Changed - Add coverage for SecurityLayer value
  • update: Suspicious Copy From or To System Directory - Update selection to use regex for better accuracy
  • update: Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock - Add the "GetRequest()" string
  • update: System File Execution Location Anomaly - add Windows error reporting binaries
  • update: System Information Discovery via Registry Queries - Enhance registry markers
  • update: Tor Client/Browser Execution - Add additional PE metadata markers

Removed / Deprecated Rules

  • remove: Active Directory Kerberos DLL Loaded Via Office Application - deprecated as it triggers on normal activity
  • remove: Atomic MacOS Stealer - FileGrabber Infostealer Execution - deprecate in favor of e710a880-1f18-4417-b6a0-b5afdf7e33da
  • remove: Space After Filename - Logic was incorrect and untested

Fixed Rules

  • fix: Capture Credentials with Rpcping.exe - Fix incorrect usage of windash with the all modifier, that broke the logic.
  • fix: Classes Autorun Keys Modification - filter null details
  • fix: Common Autorun Keys Modification - filter null
  • fix: Creation of a Local Hidden User Account by Registry - Fix the TargetObject value
  • fix: CurrentVersion Autorun Keys Modification - filter null details
  • fix: CurrentVersion NT Autorun Keys Modification - filter null and poqexec.exe
  • fix: Explorer Process Tree Break - Fix incorrect usage of windash with the all modifier, that broke the logic.
  • fix: MSDT Execution Via Answer File - Rename rule as well as introduce usage of windash for increased coverage.
  • fix: Modification of IE Registry Settings - filter null details
  • fix: Office Macro File Download - Reduce level to low due to FPs spotted via VT.
  • fix: PUA - Sysinternals Tools Execution - Registry - Fix incorrect logsource
  • fix: Potential COM Object Hijacking Via TreatAs Subkey - Registry - Change logsource and fix the rule logic
  • fix: Potential Dtrack RAT Activity - fix problematic regex with 'OR' condition
  • fix: Potential Persistence Via Logon Scripts - Registry - Fix incorrect logsource
  • fix: Potential Persistence Via New AMSI Providers - Registry - Change logsource and fix the rule logic
  • fix: Potential Persistence Via Shim Database Modification - filter null details
  • fix: Potential Product Reconnaissance Via Wmic.EXE - add filter for some product related operation through wmic
  • fix: Potential Ursnif Malware Activity - Registry - add specific registry key
  • fix: Removal Of Index Value to Hide Schedule Task - Registry - Remove EventType condition that broke the rule.
  • fix: Removal Of SD Value to Hide Schedule Task - Registry - Remove EventType condition that broke the rule.
  • fix: Scheduled Task Creation Via Schtasks.EXE - add for for msoffice application
  • fix: Scheduled TaskCache Change by Uncommon Program - filter null details
  • fix: Suspicious Certreq Command to Download - remove spaces and specific path from detection
  • fix: Suspicious CustomShellHost Execution - Increased level to high due to low FP rate spotted via VT.
  • fix: Suspicious Execution Of Renamed Sysinternals Tools - Registry - Fix incorrect logsource
  • fix: Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix - Fix selection to use ParentImage instead of Image field
  • fix: Use Short Name Path in Command Line - add filter for dotnet csc.exe
  • fix: WMIC Remote Command Execution - fix broken FP filter
  • fix: Wlrmdr.EXE Uncommon Argument Or Child Process - Fix incorrect usage of windash with the all modifier, that broke the logic.
  • fix: Wow6432Node Windows NT CurrentVersion Autorun Keys Modification - filter null

Acknowledgement

Thanks to @darses, @deftoner, @EzLucky, @frack113, @HullaBrian, @inthecyber, @JasonPhang98, @jstnk9, @Koifman, @Liran017, @montysecurity, @nasbench, @phantinuss, @RiqTam, @SethHanford, @suKTech24, @swachchhanda000, @tropChaud, @tsale, @YxinMiracle for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2025-11-01

Choose a tag to compare

@github-actions github-actions released this 29 Oct 11:28
r2025-11-01
a77d3ba

New Rules

  • new: AWS Bucket Deleted
  • new: AWS Console Login Monitoring
  • new: AWS ConsoleLogin Failed Authentication
  • new: AWS EnableRegion Command Monitoring
  • new: AWS IAM user with Console Access Login Without MFA (#5074)
  • new: AWS KMS Imported Key Material Usage
  • new: AWS STS GetCallerIdentity Enumeration Via TruffleHog
  • new: AWS VPC Flow Logs Deleted
  • new: Audit Rules Deleted Via Auditctl
  • new: BaaUpdate.exe Suspicious DLL Load
  • new: FTP Connection Open Attempt Via Winscp CLI
  • new: File Access Of Signal Desktop Sensitive Data
  • new: GitHub Repository Archive Status Changed
  • new: GitHub Repository Pages Site Changed to Public
  • new: Hacktool - EDR-Freeze Execution
  • new: IIS WebServer Log Deletion via CommandLine Utilities
  • new: ISATAP Router Address Was Set
  • new: Installation of WSL KaliLinux
  • new: Kaspersky Endpoint Security Stopped Via CommandLine - Linux
  • new: Linux Sudo Chroot Execution
  • new: Mask System Power Settings Via Systemctl
  • new: Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
  • new: PUA - Restic Backup Tool Execution
  • new: Potential Executable Run Itself As Sacrificial Process
  • new: Potential Exploitation of GoAnywhere MFT vulnerability
  • new: Potential Lateral Movement via Windows Remote Shell
  • new: Python WebServer Execution - Linux
  • new: RunMRU Registry Key Deletion
  • new: RunMRU Registry Key Deletion - Registry
  • new: Suspicious BitLocker Access Agent Update Utility Execution (#5502)
  • new: Syslog Clearing or Removal Via System Utilities
  • new: Unsigned or Unencrypted SMB Connection to Share Established
  • new: WFP Filter Added via Registry
  • new: WSL Kali Linux Usage
  • new: WinRAR Creating Files in Startup Locations
  • new: Winrs Local Command Execution
  • new: Winscp Execution From Non Standard Folder

Updated Rules

  • update: ASLR Disabled Via Sysctl or Direct Syscall - Linux - Add sysctl option
  • update: AWS Successful Console Login Without MFA - only alert on successful logins
  • update: Account Tampering - Suspicious Failed Logon Reasons - add SubStatus field
  • update: Blackbyte Ransomware Registry - move to rules-emerging-threats folder
  • update: Local Accounts Discovery - add OriginalFileName field
  • update: Modify System Firewall - add nftables delete/flush
  • update: PFX File Creation - Enhance filters, metadata and logic
  • update: Potential LSASS Process Dump Via Procdump - expand flags and service-names detection
  • update: Potentially Suspicious JWT Token Search Via CLI - add selection for common search tools
  • update: PowerShell Download Pattern - add powershell_ise
  • update: Powershell Token Obfuscation - Powershell - Move to the TH folder in order to set the right FP expectations.
  • update: Suspicious C2 Activities - update definition (#5142)
  • update: Suspicious Process Suspension via WERFaultSecure through EDR-Freeze - refine image path logic and include OriginalFileName for improved rule accuracy
  • update: Suspicious Startup Folder Persistence: add more suspicious extensions
  • update: Use Short Name Path in Image - change detection logic structure
  • update: WinRAR Execution in Non-Standard Folder - update PE metadata

Removed / Deprecated Rules

  • remove: Active Directory Parsing DLL Loaded Via Office Application - deprecated as this rule was triggered everytime any office app was opened
  • remove: Azure Application Credential Modified - superseeded by cbb67ecc-fb70-4467-9350-c910bdf7c628
  • remove: PowerShell DownloadFile - Deprecated in favour of 3b6ab547-8ec2-4991-b9d2-2b06702a48d7
  • remove: Whoami Utility Execution - Deprecated in favor of 502b42de-4306-40b4-9596-6f590c81f073

Fixed Rules

  • fix: Allow Service Access Using Security Descriptor Tampering Via Sc.EXE - filter hexnode
  • fix: Alternate PowerShell Hosts - PowerShell Module - filter out more legit powershell host
  • fix: Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE - remove + characters from selectors
  • fix: CurrentVersion Autorun Keys Modification - Add more filters for OneDriverSetup.EXE
  • fix: CurrentVersion NT Autorun Keys Modification - filter svchost making legitimate registry change
  • fix: File With Uncommon Extension Created By An Office Application - Add a filter to remove fp caused by ".com" directory filename
  • fix: Firewall Configuration Discovery Via Netsh.EXE - fix logic (#5171)
  • fix: HackTool - Windows Credential Editor (WCE) Execution - remove fp selection while increasing coverage
  • fix: Kerberoasting Activity - Initial Query - Fix issue with filter names and logic
  • fix: Mint Sandstorm - AsperaFaspex Suspicious Process Execution - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Mint Sandstorm - ManageEngine Suspicious Process Execution - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Office Application Initiated Network Connection Over Uncommon Ports - Add filter for other common ports
  • fix: Office Application Initiated Network Connection To Non-Local IP - Add filter to more legit microsoft IP address ASN subnets
  • fix: Office Autorun Keys Modification - Add a new filter for a FriendlyName Addin
  • fix: Ping Hex IP - refined detection by adding regex to only match true hexadecimal IPv4 formats
  • fix: Potential CVE-2023-23397 Exploitation Attempt - Add RemoteAddress field to filters
  • fix: Potential Data Exfiltration Activity Via CommandLine Tools - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Potential Devil Bait Malware Reconnaissance - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Potential Dtrack RAT Activity - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Potential PowerShell Obfuscation Using Alias Cmdlets - filter legitimate cim aliases
  • fix: Potential Snatch Ransomware Activity - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Potentially Suspicious Desktop Background Change Via Registry - filter EC2Launch.exe
  • fix: Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load - Add a filter for null Image field
  • fix: Program Executed Using Proxy/Local Command Via SSH.EXE - fix overlap of strings to reduce FPs
  • fix: Rare Remote Thread Creation By Uncommon Source Image - filter office FPs (#5529)
  • fix: Registry Persistence via Service in Safe Mode - filter hexnode
  • fix: SMB Create Remote File Admin Share - filter out local IP
  • fix: Startup Folder File Write - Add a filter for OneNote
  • fix: Suspicious Access to Sensitive File Extensions - Commented out groups.xml
  • fix: Suspicious Access to Sensitive File Extensions - Zeek - Commented out groups.xml
  • fix: Suspicious Network Command - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Suspicious Non PowerShell WSMAN COM Provider - filter hexnode
  • fix: Suspicious SYSTEM User Process Creation - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Suspicious Userinit Child Process - Add filter to Explorer in CommandLine
  • fix: Suspicious Volume Shadow Copy Vssapi.dll Load - Add a filter for null Image field
  • fix: Suspicious WSMAN Provider Image Loads - Add a filter for mmc loading wsman provider images
  • fix: Sysmon Channel Reference Deletion - AccessMask should be a string
  • fix: System Disk And Volume Reconnaissance via Wmic.EXE - update the rule logic to remove potential FPs
  • fix: System File Execution Location Anomaly - add filter for wsl fps
  • fix: Turla Group Commands May 2020 - Change the commandline to regex to account for additional spaces when ingesting non XML version of logs from the eventlog.
  • fix: Uncommon AppX Package Locations - Add a filter to legit Microsoft path
  • fix: Uncommon PowerShell Hosts - filter hexnode
  • fix: Usage Of Web Request Commands And Cmdlets - Comment out Net.webclient
  • fix: Usage Of Web Request Commands And Cmdlets - ScriptBlock - Commented out Net.webclient
  • fix: WannaCry Ransomware Activity - remove generic indicators (#5131)

Acknowledgement

Thanks to @adanalvarez, @BalsamicSentry, @BIitzkrieg, @CheraghiMilad, @david-syk, @djlukic, @EzLucky, @frack113, @kagebunsher, @KingKDot, @Koifman, @Liran017, @mlakri, @mm-abdelghani, @nasbench, @netgrain, @NinnessOtu, @peterydzynski, @phantinuss, @rkmbaxed, @RobertN87, @saakovv, @swachchhanda000, @thuya-hacktilizer, @toopricey, @vasquja, @vl43den, @YamatoSecurity, @zambomarcell for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2025-10-01

Choose a tag to compare

@github-actions github-actions released this 01 Oct 12:54
r2025-10-01
d27d120

New Rules

  • new: ADExplorer Writing Complete AD Snapshot Into .dat File
  • new: CrushFTP RCE vulnerability CVE-2025-54309
  • new: Delete Defender Scan ShellEx Context Menu Registry Key
  • new: Disabling Windows Defender WMI Autologger Session via Reg.exe
  • new: FunkLocker Ransomware File Creation
  • new: Low Reputation Effective Top-Level Domain (eTLD)
  • new: MMC Executing Files with Reversed Extensions Using RTLO Abuse
  • new: MMC Loading Script Engines DLLs
  • new: MacOS FileGrabber Infostealer
  • new: NodeJS Execution of JavaScript File
  • new: Password Never Expires Set via WMI
  • new: Potential ClickFix Execution Pattern - Registry
  • new: Potential Hello-World Scraper Botnet Activity
  • new: Potential JLI.dll Side-Loading
  • new: Potential PowerShell Console History File Access Attempt
  • new: Potential SAP NetWeaver Webshell Creation
  • new: Potential SAP NetWeaver Webshell Creation - Linux
  • new: Potential SSH Tunnel Persistence Install Using A Scheduled Task
  • new: Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
  • new: Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
  • new: Potentially Suspicious Child Processes Spawned by ConHost
  • new: Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
  • new: PowerShell Defender Default Threat Action Set to 'Allow' or 'NoAction'
  • new: Registry Manipulation via WMI Stdregprov
  • new: Remote Access Tool - TacticalRMM Agent Registration to Potential Attacker-Controlled Server
  • new: Scheduled Task Creation Masquerading as System Processes
  • new: Schtasks Curl Download and Powershell Execution Combination
  • new: Security Event Logging Disabled Via MiniNt Registry Key - Process
  • new: Security Event Logging Disabled Via MiniNt Registry Key - Registry Set
  • new: SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS
  • new: Suspicious Child Process of SAP NetWeaver
  • new: Suspicious Child Process of SAP NetWeaver - Linux
  • new: Suspicious Creation of .library-ms File - Potential CVE-2025-24054 Exploit
  • new: Suspicious File Created in Outlook Temporary Directory
  • new: Suspicious File Write to SharePoint Layouts Directory
  • new: Suspicious Process Suspension via WERFaultSecure through EDR-Freeze
  • new: Suspicious Uninstall of Windows Defender Feature via PowerShell
  • new: Suspicious Velociraptor Child Process
  • new: WDAC Policy File Creation In CodeIntegrity Folder
  • new: Windows Defender Context Menu Removed via Reg.exe
  • new: Windows Defender Default Threat Action Modified
  • new: Windows Recovery Environment Disabled Via Reagentc

Updated Rules

  • update: Active Directory Database Snapshot Via ADExplorer - add more selections
  • update: Certificate Use With No Strong Mapping - Update Provider Name
  • update: Change User Agents with WebRequest - add invoke-restmethod cmdlet
  • update: DNS Query Tor .Onion Address - Sysmon - update detection logic
  • update: DNS TOR Proxies - update detection logic
  • update: KDC RC4-HMAC Downgrade CVE-2022-37966 - Update Provider Name
  • update: Network Connection Initiated To BTunnels Domains - MITRE tags
  • update: Network Connection Initiated To Cloudflared Tunnels Domains - MITRE tags
  • update: Network Connection Initiated To DevTunnels Domain - MITRE tags
  • update: Network Connection Initiated To Mega.nz - MITRE tag
  • update: Network Connection Initiated To Visual Studio Code Tunnels Domain - MITRE tags
  • update: No Suitable Encryption Key Found For Generating Kerberos Ticket - Update Provider Name
  • update: Obfuscated IP Download Activity - add invoke-restmethod cmdlet
  • update: Potential DLL File Download Via PowerShell Invoke-WebRequest - add invoke-restmethod cmdlet
  • update: Potential Data Exfiltration Activity Via CommandLine Tools - add invoke-restmethod cmdlet
  • update: Potential Defense Evasion Via Binary Rename - add 7za
  • update: Potential Defense Evasion Via Right-to-Left Override - add [U+202E]
  • update: Potential File Extension Spoofing Using Right-to-Left Override - add [U+202E] and more extensions
  • update: Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create - update rule with new IOCs
  • update: PowerShell Download and Execution Cradles - add invoke-restmethod cmdlet
  • update: PowerShell Script With File Upload Capabilities - add invoke-restmethod cmdlet
  • update: Python Image Load By Non-Python Process - update the metadata
  • update: Query Tor Onion Address - DNS Client - update detection logic
  • update: Regsvr32 DLL Execution With Suspicious File Extension - add coverage for regsvr executing '.log' extension
  • update: Renamed Visual Studio Code Tunnel Execution - remove optional flag '--name'
  • update: RestrictedAdminMode Registry Value Tampering - ProcCreation - remove trailing slash
  • update: Suspicious Active Directory Database Snapshot Via ADExplorer - add more selections
  • update: Suspicious Double Extension Files - add .svg extension
  • update: Suspicious Dropbox API Usage - MITRE tags
  • update: Suspicious Get Local Groups Information - PowerShell - increase coverage for WMI modules
  • update: Suspicious Invoke-WebRequest Execution - add powershell_ise
  • update: Suspicious Invoke-WebRequest Execution With DirectIP - add invoke-restmethod cmdlet
  • update: Suspicious Non-Browser Network Communication With Telegram API - MITRE tag
  • update: Suspicious PowerShell In Registry Run Keys - add invoke-restmethod cmdlet
  • update: Suspicious Windows Service Tampering - add coverage for Windows service tampering through wmic and PowerShell WMI module
  • update: System File Execution Location Anomaly - add taskhostw
  • update: Unsigned DLL Loaded by Windows Utility - also filter SignatureStatus 'valid'
  • update: Usage Of Web Request Commands And Cmdlets - ScriptBlock - add invoke-restmethod cmdlet
  • update: Usage Of Web Request Commands And Cmdlets - add invoke-restmethod cmdlet
  • update: Visual Studio Code Tunnel Execution - remove optional flag '--name'

Removed / Deprecated Rules

  • remove: .RDP File Created by Outlook Process - deprecate in favour of fabb0e80-030c-4e3e-a104-d09676991ac3
  • remove: PowerShell Web Download - deprecate duplicate rule in favour of 9fc51a3c-81b3-4fa7-b35f-7c02cf10fd2d

Fixed Rules

  • fix: Added Credentials to Existing Application - fix filter dash type, capitalization and spaces to match Azure log format
  • fix: COM Hijacking via TreatAs - Add filter for integrator.exe
  • fix: HackTool - LaZagne Execution - remove imphashes common to pyinstaller bundled executables
  • fix: New Service Creation Using Sc.EXE - add filter for dropbox
  • fix: Potential Defense Evasion Via Raw Disk Access By Uncommon Tools - add filter for mpDefenderCoreService and SysWow64
  • fix: Potential Persistence Via Notepad++ Plugins - add filter for notepad++ installers
  • fix: Potential PsExec Remote Execution - add filter for localhost
  • fix: Potential Python DLL SideLoading - add FP filter caused by pyinstaller bundled applications
  • fix: Process Initiated Network Connection To Ngrok Domain - fix title and update MITRE tags
  • fix: Removal of Potential COM Hijacking Registry Keys - Added Msedge update filter
  • fix: Suspicious Volume Shadow Copy VSS_PS.dll Load - add vssadmin filter
  • fix: Transferring Files with Credential Data via Network Shares - Made the string matching little more specific to avoid FPs
  • fix: UNC4841 - Barracuda ESG Exploitation Indicators - FPs with mknod on Linux systems
  • fix: Windows Binaries Write Suspicious Extensions - Add filter for PowerShell files created by svchost in the Clipchamp folder.
  • fix: Windows Event Log Access Tampering Via Registry
  • fix: potentially suspicious execution from tmp folder
  • fix: potentially suspicious execution from tmp folder - nextcloud fp from tmp folder

Acknowledgement

Thanks to @0xbcf, @0xPrashanthSec, @egycondor, @EzLucky, @frack113, @gkazimiarovich, @JasonPhang98, @josamontiel, @Koifman, @Liran017, @M1ra1B0T, @MATTANDERS0N, @nasbench, @Neo23x0, @netgrain, @nisargsuthar, @norbert791, @peterydzynski, @phantinuss, @resp404nse, @ruppde, @swachchhanda000, @Ti-R, @vl43den, @YxinMiracle for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2025-07-08

Choose a tag to compare

@github-actions github-actions released this 08 Jul 11:32
r2025-07-08
a55bc21

New Rules

  • new: Attempts of Kerberos Coercion Via DNS SPN Spoofing
  • new: BITS Client BitsProxy DLL Loaded By Uncommon Process
  • new: Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
  • new: DNS Query To Common Malware Hosting and Shortener Services
  • new: DNS Query To Katz Stealer Domains
  • new: DNS Query To Katz Stealer Domains - Network
  • new: Disable ASLR Via Personality Syscall - Linux
  • new: FileFix - Command Evidence in TypedPaths from Browser File Upload Abuse
  • new: FileFix - Suspicious Child Process from Browser File Upload Abuse
  • new: HKTL - SharpSuccessor Privilege Escalation Tool Execution
  • new: HackTool - Doppelanger LSASS Dumper Execution
  • new: HackTool - HollowReaper Execution
  • new: HackTool - Impacket File Indicators
  • new: Katz Stealer DLL Loaded
  • new: Katz Stealer Suspicious User-Agent
  • new: MSSQL Destructive Query
  • new: Obfuscated PowerShell MSI Install via WindowsInstaller COM
  • new: Potential AS-REP Roasting via Kerberos TGT Requests
  • new: Potential Abuse of Linux Magic System Request Key
  • new: Potential Exploitation of RCE Vulnerability CVE-2025-33053
  • new: Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
  • new: Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
  • new: Potential Java WebShell Upload in SAP NetViewer Server
  • new: Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation
  • new: Potential Notepad++ CVE-2025-49144 Exploitation
  • new: Potential SAP NetViewer Webshell Command Execution
  • new: PowerShell MSI Install via WindowsInstaller COM From Remote Location
  • new: Proxy Execution via Vshadow - detect invocation of vshadow.exe with -exec to spot hidden malware execution
  • new: RegAsm.EXE Execution Without CommandLine Flags or Files
  • new: Registry Export of Third-Party Credentials
  • new: Remote Access Tool - Potential MeshAgent Usage - MacOS
  • new: Remote Access Tool - Potential MeshAgent Usage - Windows
  • new: Remote Access Tool - Suspicious MeshAgent Usage - MacOS
  • new: Remote Access Tool - Suspicious MeshAgent Usage - Windows
  • new: Special File Creation via Mknod Syscall
  • new: Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
  • new: Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network
  • new: Suspicious Deno File Written from Remote Source
  • new: Suspicious Download and Execute Pattern via Curl/Wget
  • new: Suspicious File Access to Browser Credential Storage
  • new: System Info Discovery via Sysinfo Syscall
  • new: System Information Discovery via Registry Queries
  • new: Trusted Path Bypass via Windows Directory Spoofing

Updated Rules

  • update: Access of Sudoers File Content - add more tools
  • update: AspNetCompiler Execution - Add ARM version of the \Microsoft.NET path
  • update: Audio Capture - use syscall name instead of id
  • update: Cisco Modify Configuration - add "ntp server" keyword
  • update: Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall - use syscall name instead of id
  • update: Commands to Clear or Remove the Syslog - detect journald vacuuming
  • update: Disable ASLR Via Personality Syscall - Linux - use syscall name instead of id
  • update: Disable Internal Tools or Feature in Registry - More registry modifications associated with feature change of windows internal tools added
  • update: Enumeration for 3rd Party Creds From CLI - Updated the condition to update FP
  • update: File Decoded From Base64/Hex Via Certutil.EXE - Increase level to high
  • update: FileFix - Suspicious Child Process from Browser File Upload Abuse - add cmd.exe child process
  • update: HackTool - LaZagne Execution: filter added to reduce FP and added more coverage through imphash
  • update: Local Groups Discovery - Linux - add text output tools
  • update: MSHTA Execution with Suspicious File Extensions - title changed and more susp extension added
  • update: Malicious PowerShell Commandlets - PoshModule - Add BadSuccessor Exploit
  • update: Malicious PowerShell Commandlets - PoshModule - add Invoke-PowerDPAPI
  • update: Malicious PowerShell Commandlets - ProcessCreation - add Invoke-PowerDPAPI
  • update: Malicious PowerShell Commandlets - ScriptBlock - add Invoke-PowerDPAPI
  • update: Malicious PowerShell Scripts - FileCreation - Add BadSuccessor Exploit
  • update: Malicious PowerShell Scripts - FileCreation - add Invoke-PowerDPAPI
  • update: Malicious PowerShell Scripts - PoshModule - Add BadSuccessor Exploit
  • update: Malicious PowerShell Scripts - PoshModule - add Invoke-PowerDPAPI
  • update: Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image - add Unicode space character
  • update: Potential PowerShell Obfuscation Via WCHAR/CHAR - Add CHAR variation
  • update: Potentially Suspicious ASP.NET Compilation Via AspNetCompiler - Add ARM version of the \Microsoft.NET path
  • update: Program Executed Using Proxy/Local Command Via SSH.EXE - add Imphash and OriginalFileName
  • update: Remote Thread Created In Shell Application - move to threat-hunting folder as it causes too much noise
  • update: Suspicious Double Extension File Execution: add more suspicious extension combination
  • update: Suspicious Double Extension Files: add more suspicious extension combination
  • update: Suspicious SignIns From A Non Registered Device - add null value in addition to empty string
  • update: Suspicious Windows Defender Registry Key Tampering Via Reg.EXE - Increase coverage by adding new values that allow for Windows Defender to be disabled such as DisableCloudProtection and DisableSecurityCenter
  • update: System Owner or User Discovery - Linux - add uname
  • update: TrustedPath UAC Bypass Pattern - update Image value
  • update: Webshell Remote Command Execution - add execveat and match on euid instead of key

Fixed Rules

  • fix: ADS Zone.Identifier Deleted By Uncommon Application - filter msedge
  • fix: AddinUtil.EXE Execution From Uncommon Directory - Add filter for Windows Microsoft.NET ARM path
  • fix: Amsi.DLL Load By Uncommon Process - Add filter for Windows Microsoft.NET ARM path
  • fix: Common Autorun Keys Modification - add 64 bits Program Files directory in filter
  • fix: Creation of an Executable by an Executable - Add filter for Windows Microsoft.NET ARM path
  • fix: CurrentVersion Autorun Keys Modification - add 64 bits Program Files directory in filter
  • fix: CurrentVersion NT Autorun Keys Modification - add filter for RuntimeBroker.exe
  • fix: Hidden Files and Directories - reduce FP matching with regex pattern
  • fix: MSSQL Server Failed Logon From External Network - filter for local_machine without IP
  • fix: Modification of IE Registry Settings - add filter for RuntimeBroker.exe
  • fix: Potential AS-REP Roasting via Kerberos TGT Requests - use the correct PreAuthType selection field name
  • fix: Potential Active Directory Reconnaissance/Enumeration Via LDAP - commenting out troublesome LDAP query parameter
  • fix: Potential Binary Or Script Dropper Via PowerShell - add filters for legitimate binary dropped by PowerShell
  • fix: Potential DLL Sideloading Of MsCorSvc.DLL - Add filter for Windows Microsoft.NET ARM path
  • fix: Potential System DLL Sideloading From Non System Locations - Add filter for "C:\Windows\SyChpe32"
  • fix: PowerShell Core DLL Loaded By Non PowerShell Process - Add filter for Windows Microsoft.NET ARM path
  • fix: Rare Remote Thread Creation By Uncommon Source Image - add new filters to reduce noise
  • fix: Remote Thread Created In Shell Application - modify the logic to filter out legit processes creating remote thread in shell apps
  • fix: Remote Thread Creation By Uncommon Source Image - add new filters to reduce noise
  • fix: Remote Thread Creation In Uncommon Target Image - add FP filters for notepad and sethc
  • fix: Scheduled TaskCache Change by Uncommon Program - add filter for RuntimeBroker.exe
  • fix: Suspicious Sysmon as Execution Parent - add filter for Sysmon binary running from temp dir
  • fix: Suspicious Userinit Child Process - filter null Image
  • fix: Suspicious WSMAN Provider Image Loads - Add filter for Windows Microsoft.NET ARM path
  • fix: Uncommon AppX Package Locations - add a new filter to reduce noise
  • fix: Use Short Name Path in Command Line - add filter for aurora
  • fix: WMI Module Loaded By Uncommon Process - Add filter for Windows Microsoft.NET ARM path

Acknowledgement

Thanks to @0xFustang, @ajpc500, @ariel-anieli, @CheraghiMilad, @dan21san, @david-syk, @egycondor, @EzLucky, @frack113, @gregorywychowaniec-zt, @GrepItAll, @hashdr1ft, @joshnck, @JrOrOneEquals1, @kivi280, @MalGamy12, @nasbench, @nikstuckenbrock, @norbert791, @phantinuss, @swachchhanda000, @unicornofhunt, @vx3r, @wieso-itzi, @X-Junior, @xlazarg for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2025-05-21

Choose a tag to compare

@github-actions github-actions released this 27 May 11:13
304b019

New Rules

  • new: Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
  • new: Crash Dump Created By Operating System
  • new: HTTP Request to Low Reputation TLD or Suspicious File Extension
  • new: Kalambur Backdoor Curl TOR SOCKS Proxy Execution
  • new: Notepad Password Files Discovery
  • new: PUA - AdFind.EXE Execution
  • new: PUA - NimScan Execution
  • new: Potential CVE-2024-35250 Exploitation Activity
  • new: Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
  • new: Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
  • new: Potentially Suspicious WDAC Policy File Creation
  • new: Suspicious Autorun Registry Modified via WMI
  • new: Suspicious CrushFTP Child Process
  • new: Suspicious LNK Command-Line Padding with Whitespace Characters
  • new: Suspicious Process Spawned by CentreStack Portal AppPool

Updated Rules

  • update: AADInternals PowerShell Cmdlets Execution - ProccessCreation - Add additional strings from the AADinternals framework
  • update: AADInternals PowerShell Cmdlets Execution - PsScript - Add additional strings from the AADinternals framework
  • update: AWS New Lambda Layer Attached - Enhance metadata and logic
  • update: Anydesk Remote Access Software Service Installation - Enhance coverage by accounting for the AnyDesk MSI Service
  • update: Audio Capture - add ecasound detection
  • update: Buffer Overflow Attempts - Enhance and reworked logic with new keywords
  • update: COM Object Hijacking Via Modification Of Default System CLSID Default Value - Add additional COM CLSID
  • update: Direct Autorun Keys Modification
  • update: Elevated System Shell Spawned - Add powershell_ise
  • update: Elevated System Shell Spawned From Uncommon Parent Location - Add powershell_ise
  • update: Malicious PowerShell Commandlets - PoshModule - Add Veeam-Get-Creds
  • update: Malicious PowerShell Commandlets - ProcessCreation - Add Veeam-Get-Creds
  • update: Malicious PowerShell Scripts - FileCreation - Add Veeam-Get-Creds.ps1
  • update: Malicious PowerShell Scripts - PoshModule - Add Veeam-Get-Creds.ps1
  • update: New RUN Key Pointing to Suspicious Folder
  • update: Nslookup PowerShell Download Cradle - Add additional coverage with -type=txt http
  • update: Obfuscated PowerShell OneLiner Execution - Enhance logic to increase coverage.
  • update: Potential APT FIN7 Exploitation Activity - Add false positive description
  • update: Potential Binary Impersonating Sysinternals Tools - Add list of binaries compiled for Arm64 arch added
  • update: Potential Browser Data Stealing - add esentutl.exe
  • update: Potential Obfuscated Ordinal Call Via Rundll32 - Add additional obfuscation methods
  • update: Potential Persistence Attempt Via Run Keys Using Reg.EXE
  • update: Potential Product Class Reconnaissance Via Wmic.EXE - Add AntiSpywareProduct class
  • update: Potentially Suspicious WDAC Policy File Creation
  • update: Process Memory Dump Via Comsvcs.DLL - Add additional obfuscation methods
  • update: Remote Access Tool - AnyDesk Execution - Add AnyDeskMSI.exe
  • update: Remote Access Tool - AnyDesk Incoming Connection - Add AnyDeskMSI.exe
  • update: Remote Access Tool - Anydesk Execution From Suspicious Folder - Add AnyDeskMSI.exe
  • update: Renamed AdFind Execution - Add additional Imphash values
  • update: Service Reload or Start - Linux - Add additional flags and binaries used to changes services status
  • update: Suspicious Binary Writes Via AnyDesk - Add AnyDeskMSI.exe
  • update: Suspicious Eventlog Clear - Added coverage for eventlog clearing using dotnet class
  • update: Suspicious Eventlog Clearing or Configuration Change Activity- Added coverage for eventlog clearing using dotnet class
  • update: Suspicious PowerShell Invocations - Specific
  • update: Suspicious PowerShell Invocations - Specific - PowerShell Module
  • update: Suspicious Powershell In Registry Run Keys
  • update: Suspicious Run Key from Download
  • update: Windows Event Log Access Tampering Via Registry - Increase coverage by removing log markers
  • update: proc_creation_lnx_esxcli_network_discovery.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_permission_change_admin.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_storage_discovery.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_syslog_config_change.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_system_discovery.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_user_account_creation.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_vm_discovery.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_vm_kill.yml - updating MITRE to match v17
  • update: proc_creation_lnx_esxcli_vsan_discovery.yml - updating MITRE to match v17

Fixed Rules

  • fix: Conhost Spawned By Uncommon Parent Process - Add filter for '-k wusvcs -p -s WaaSMedicSvc
  • fix: Indirect Command Exectuion via Forfiles - wrong keyword
  • fix: Potential Binary Or Script Dropper Via PowerShell - Add filter for C:\Windows\SystemTemp\
  • fix: Potential CVE-2023-23397 Exploitation Attempt - SMB - Add filters for IP format when ingesting XML raw event
  • fix: Potential CVE-2023-23397 Exploitation Attempt - SMB - Fix the IP block covering EventID 30804 as it does not contain an IP as a field but as a string
  • fix: Potential WinAPI Calls Via CommandLine - Add new filter for CompatTelRunner
  • fix: PowerShell Execution - wrong date format
  • fix: Python Initiated Connection - Add filter for pip install
  • fix: Python Initiated Connection - Enhance python filter
  • fix: Python Inline Command Execution - Add filter for whl package installations
  • fix: Schtasks Creation Or Modification With SYSTEM Privileges - Add new filter of office scheduled task
  • fix: Whoami.EXE Execution Anomaly - Add new filter for empty parent
  • fix: Windows Processes Suspicious Parent Directory - Add new filter for empty parent

Acknowledgement

Thanks to @CheraghiMilad, @clr2of8, @david-syk, @DFIR-Detection, @dsplice, @Eyezuhk, @frack113, @Gude5, @HannesWid, @imall4n, @jasonmull, @Koifman, @MalGamy12, @nasbench, @Neo23x0, @nickatrecon, @phantinuss, @RG9n, @signalblur, @swachchhanda000, @whichbuffer, @X-Junior for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2025-02-03

Choose a tag to compare

@github-actions github-actions released this 03 Feb 17:34
2bfb093

New Rules

  • new: Azure Login Bypassing Conditional Access Policies
  • new: CVE-2024-49113 Exploitation Attempt - LDAP Nightmare
  • new: Suspicious Binaries and Scripts in Public Folder
  • new: Suspicious Invocation of Shell via Rsync
  • new: Windows Event Log Access Tampering Via Registry

Updated Rules

  • update: Exploit Framework User Agent - Add default Havoc C2 UA
  • update: Renamed Powershell Under Powershell Channel - Update regex to use \s+ to account for different parsers
  • update: Shell Execution via Rsync - Linux - Rework logic to make it more generic and include additional shells.
  • update: Suspicious Non PowerShell WSMAN COM Provider - Update regex to use \s+ to account for different parsers
  • update: Suspicious Windows Service Tampering - Add additional services

Removed / Deprecated Rules

  • remove: Windows Defender Exclusion Deleted

Fixed Rules

  • fix: BITS Transfer Job With Uncommon Or Suspicious Remote TLD - Add dn.onenote.net/ and cdn.office.net/
  • fix: CodeIntegrity - Unmet Signing Level Requirements By File Under Validation - Add filter for Kaspersky and mDNS Responder
  • fix: Failed Code Integrity Checks - Add filters for CrowdStrike.
  • fix: Forest Blizzard APT - Process Creation Activity - prepend SHA256 to hash value
  • fix: HackTool - Dumpert Process Dumper Execution - prepend MD5 to hash value
  • fix: ManageEngine Endpoint Central Dctask64.EXE Potential Abuse - prepend IMPHASH to hash value
  • fix: Potential CVE-2023-36874 Exploitation - Fake Wermgr.Exe Creation - Add filter for \Windows\SoftwareDistribution\Download\
  • fix: Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load - Add exclusion filter C:\ProgramData\Package Cache\{ to account for cases like the execution of vcredist
  • fix: Privileged User Has Been Created - Add missing comma to avoid false positives
  • fix: Relevant Anti-Virus Signature Keywords In Application Log - Enhances the HTool string to avoid unintended matches.
  • fix: Renamed Powershell Under Powershell Channel - Add edge case filters for double backslashes PowerShell invocation.
  • fix: Renamed ZOHO Dctask64 Execution - prepend IMPASH to hash value
  • fix: Uncommon AppX Package Locations - Add https://installer.teams.static.microsoft/
  • fix: WCE wceaux.dll Access - Remove EventIDs 4658 and 4660 as they both do not contain the ObjectName field

Acknowledgement

Thanks to @DanielKoifman, @defensivedepth, @djlukic, @frack113, @GtUGtHGtNDtEUaE, @joshnck, @krdmnbrk, @nasbench, @Neo23x0, @samuelmonsempessenthorus, @Ti-R, @tsale, @X-Junior for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.

Release r2024-12-19

Choose a tag to compare

@github-actions github-actions released this 19 Dec 19:46
e8a6894

New Rules

  • new: AWS Key Pair Import Activity
  • new: AWS SAML Provider Deletion Activity
  • new: CVE-2024-50623 Exploitation Attempt - Cleo
  • new: DNS Query Request By QuickAssist.EXE
  • new: Lummac Stealer Activity - Execution Of More.com And Vbc.exe
  • new: Modification or Deletion of an AWS RDS Cluster
  • new: New AWS Lambda Function URL Configuration Created
  • new: Potential File Extension Spoofing Using Right-to-Left Override
  • new: Potentially Suspicious Azure Front Door Connection
  • new: QuickAssist Execution
  • new: Setup16.EXE Execution With Custom .Lst File
  • new: Suspicious ShellExec_RunDLL Call Via Ordinal

Updated Rules

  • update: App Assigned To Azure RBAC/Microsoft Entra Role - Add a constraint to limit the detection to service principal only
  • update: COM Object Hijacking Via Modification Of Default System CLSID Default Value - Add 2 new additional built-in COM object GUID that were seen being used for hijacking
  • update: COM Object Hijacking Via Modification Of Default System CLSID Default Value - Add {603D3801-BD81-11d0-A3A5-00C04FD706EC}
  • update: DNS Query To Remote Access Software Domain From Non-Browser App - Add getscreen.me
  • update: File and Directory Discovery - Linux - Add 2 additional binaries, "findmnt" and "mlocate"
  • update: GALLIUM IOCs - remove custom dedicated hash fields
  • update: HackTool - CoercedPotato Execution - remove custom dedicated hash fields
  • update: HackTool - CreateMiniDump Execution - remove custom dedicated hash fields
  • update: HackTool - GMER Rootkit Detector and Remover Execution - remove custom dedicated hash fields
  • update: HackTool - HandleKatz LSASS Dumper Execution - remove custom dedicated hash fields
  • update: HackTool - Impersonate Execution - remove custom dedicated hash fields
  • update: HackTool - LocalPotato Execution - remove custom dedicated hash fields
  • update: HackTool - PCHunter Execution - remove custom dedicated hash fields
  • update: HackTool - PPID Spoofing SelectMyParent Tool Execution - remove custom dedicated hash fields
  • update: HackTool - SharpEvtMute DLL Load - remove custom dedicated hash fields
  • update: HackTool - Stracciatella Execution - remove custom dedicated hash fields
  • update: HackTool - SysmonEOP Execution - remove custom dedicated hash fields
  • update: HackTool - UACMe Akagi Execution - remove custom dedicated hash fields
  • update: HackTool - Windows Credential Editor (WCE) Execution - remove custom dedicated hash fields
  • update: HackTool Named File Stream Created - remove custom dedicated hash fields
  • update: Hacktool Execution - Imphash - remove custom dedicated hash fields
  • update: Local System Accounts Discovery - Linux - Add additional binaries to read password files such as "less" and "emacs" as well as additional password file locations such as "/etc/pwd.db"
  • update: Mail Forwarding/Redirecting Activity In O365 - Add additional parameters to increase coverage
  • update: Malicious DLL Load By Compromised 3CXDesktopApp - remove custom dedicated hash fields
  • update: MpiExec Lolbin - remove custom dedicated hash fields
  • update: PUA - Fast Reverse Proxy (FRP) Execution - remove custom dedicated hash fields
  • update: PUA - NPS Tunneling Tool Execution - remove custom dedicated hash fields
  • update: PUA - Nimgrab Execution - remove custom dedicated hash fields
  • update: PUA - Process Hacker Driver Load - remove custom dedicated hash fields
  • update: PUA - Process Hacker Execution - remove custom dedicated hash fields
  • update: PUA - System Informer Driver Load - remove custom dedicated hash fields
  • update: PUA - System Informer Execution - remove custom dedicated hash fields
  • update: PUA- IOX Tunneling Tool Execution - remove custom dedicated hash fields
  • update: Password Policy Discovery - Linux - Add additional new paths for "pam.d" , namely "/etc/pam.d/common-account", "/etc/pam.d/common-auth" and "/etc/pam.d/auth"
  • update: Potential Compromised 3CXDesktopApp Execution - remove custom dedicated hash fields
  • update: Potential Defense Evasion Via Rename Of Highly Relevant Binaries - Add ie4uinit.exe and msxsl.exe to old binary rename rule
  • update: Potential Secure Deletion with SDelete - Enhance metadata
  • update: Potential SquiblyTwo Technique Execution - remove custom dedicated hash fields
  • update: Potentially Suspicious Cabinet File Expansion - Add new paths for built-in shares
  • update: Process Discovery - Add additional processes like "htop" and "atop"
  • update: Remote Access Tool - NetSupport Execution From Unusual Location - remove custom dedicated hash fields
  • update: Remote Access Tool Services Have Been Installed - Security - Add anydesk
  • update: Renamed AdFind Execution - remove custom dedicated hash fields
  • update: Renamed AutoIt Execution - remove custom dedicated hash fields
  • update: Renamed NetSupport RAT Execution - remove custom dedicated hash fields
  • update: Renamed PAExec Execution - remove custom dedicated hash fields
  • update: System Owner or User Discovery - Linux - Add 4 additional tools that can be used for host and user discovery: "whoami", "hostname", "id", "last"
  • update: Terminate Linux Process Via Kill - Add "xkill"
  • update: Vulnerable HackSys Extreme Vulnerable Driver Load - remove custom dedicated hash fields
  • update: Vulnerable WinRing0 Driver Load - remove custom dedicated hash fields
  • update: Webshell Detection With Command Line Keywords - Add suspicious powershell commandline keywords
  • update: WinDivert Driver Load - remove custom dedicated hash fields

Fixed Rules

  • fix: Creation of WerFault.exe/Wer.dll in Unusual Folder - Add filter for windows update/installation folder C:\Windows\SoftwareDistribution\
  • fix: FPs with NetNTLM downgrade attack (#5108)
  • fix: NetNTLM Downgrade Attack - Registry - Tune the rule for specific registry values in order to reduce FP rate.
  • fix: Suspicious Process By Web Server Process - Fix typo in "ntdsutil" process name
  • fix: Suspicious SYSTEM User Process Creation - filter false positives with Google Updater uninstall script
  • fix: bXOR Operator Usage In PowerShell Command Line - PowerShell Classic - Update the logic to remove unrelated keywords and reduce unwanted matches.

Acknowledgement

Thanks to @AlbinoGazelle, @CheraghiMilad, @cod3nym, @dan21san, @djlukic, @faisalusuf, @frack113, @gregorywychowaniec-zt, @IsaacDunham, @jstnk9, @Koifman, @MalGamy12, @mgreen27, @nasbench, @Neo23x0, @randomaccess3, @saakovv, @swachchhanda000 for their contribution to this release

Which Sigma rule package should I use?

A detailed explanation can be found in the Releases.md file. If you are new to Sigma, we recommend starting with the "Core" ruleset.

The latest release package on GitHub can always be found here.