Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows file creation of code_tunnel.json outside Code/VsCode executables
Alerts on creation of code_tunnel.json on Windows when it isn’t created by typical VS Code binaries.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh151Free2023-10-25Windows File Creation by VS Code Tunnel node.exe in .vscode-server History
Alerts on node.exe creating files under .vscode-server User History when the process runs from a VS Code server tunnel path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium142Free2023-10-25Windows DNS Queries to Visual Studio Code Tunnel Domains
Alerts on Windows DNS queries to .tunnels.api.visualstudio.com, matching Visual Studio Code tunnel endpoints.
citron_ninja, Huntrule TeamWindowsdns_queryMedium189Free2023-10-25Windows DNS Queries to Devtunnels .devtunnels.ms Domains
Alerts on Windows DNS queries for .devtunnels.ms domains, which may indicate DevTunnels-based C2 or persistence.
citron_ninja, Huntrule TeamWindowsdns_queryMedium112Free2023-10-25Windows Process Execution of findstr.EXE for Security Tool Keyword Filtering
Alerts on Windows findstr.exe executions that filter output using security software and antivirus-related keywords.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium182Free2023-10-20Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsfile_eventHigh368Free2023-10-19Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWindowsregistry_setLow132Free2023-10-18Windows Process Execution: curl.exe Downloading Files From an IP URL
Flags curl.exe commands that download via an IP-based URL using output/remote-name flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium383Free2023-10-18Windows CertOC.exe Downloads File From IP-Based URL Using -GetCACAPS
Flags CertOC.exe executions using an IP-based URL in the command line with -GetCACAPS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2023-10-18Windows Process Creation: CoercedPotato.exe Execution via ExploitId Parameters
Flags Windows process creation for CoercedPotato.exe with --exploitId and known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh253Free2023-10-11Windows Named Pipe Creation with "\coerced\" PipeName Segment
Detects Windows named pipe creations where the pipe name contains the '\coerced\' pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdHigh132Free2023-10-11Windows MSSQL Failed Logon (EventID 18456) From External Client IP
Alerts on MSSQL failed login attempts (Event 18456) from client IPs outside typical local/private ranges.
j4son, Huntrule TeamWindowsapplicationMedium113Free2023-10-11Windows MSSQL Failed Logon (Event ID 18456) Detection
Alerts on MSSQL-related failed login attempts (Event ID 18456) captured in Windows application logs.
Nasreddine Bencherchali (Nextron Systems), j4son, Huntrule TeamWindowsapplicationLow80Free2023-10-11Windows ScreenConnect RMM System Command Execution via cmd.exe
Flags cmd.exe launched by ScreenConnect.ClientService.exe with a TEMP\ScreenConnect command-line path.
Ali Alwashali, Huntrule TeamWindowsprocess_creationLow131Free2023-10-10Windows: ScreenConnect Temporary File Creation in ConnectWiseControl Temp
Flags file writes to ScreenConnect’s ConnectWiseControl\Temp staging directory from ScreenConnect.WindowsClient.exe.
Ali Alwashali, Huntrule TeamWindowsfile_eventLow82Free2023-10-10