{"repo":"mdecrevoisier/SIGMA-detection-rules","free":true,"listed":false,"github":"https://github.com/mdecrevoisier/SIGMA-detection-rules","clone":"git clone https://github.com/mdecrevoisier/SIGMA-detection-rules.git","description":"Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques","language":null,"stars":441,"topics":["sigma","windows","mitre-attack","threat-hunting","powershell"],"license":"CC0-1.0","category":"cli-tools","readme_excerpt":"SIGMA detection rules Project purpose: SIGMA detection rules provides a free set of 350 advanced correlation rules to be used for suspicious hunting activities. How to use the rules: The SIGMA rules can be used in different ways together with your SIEM: Using the native SIGMA converter: https://github.com/SigmaHQ/sigma Using SOC Prime online SIGMA converter: https://uncoder.io/ Using the SOC Prime free Kibana plugin: https://github.com/socprime/SigmaUI Microsoft products used: Windows 10 Windows Server 2016 Active Directory Domain Services (ADDS) Active Directory Certification Services (ADCS / PKI) with online responder (OCSP) SQL Server 2014 Windows Defender Active Directory Certificate Services (ADCS) SYSMON v11 and higher Exchange 2016 Internet Information Services (IIS web server) SIGMA rules content Att@ck Tactic Att@ck Technique Description Event IDs Threat name / Tool / CVE :------------------------- :------------------ :------------------------- :------------------ :------------------ Antivirus Antivirus Defender: antivirus not up to date 1151 Antivirus Antivirus Defender: massive malware outbreak detected on multiple hosts 1116 Antivirus Antivirus Defender: massive malwares detected on a single host 1116 TA0001-Initial access T1078.002-Valid accounts-Domain accounts Login denied due to account policy restrictions 4625 TA0001-Initial access T1078.002-Valid accounts-Domain accounts Login failure from a single source with a disabled account 33205 TA0001-Initial access T","default_branch":null,"files":null,"tree":[],"storefront":"/r/mdecrevoisier","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mdecrevoisier/SIGMA-detection-rules/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}