Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows process activity matching Winnti malware traits from ProgramData\DRM paths
Detects suspicious Winnti-like execution where ProgramData\DRM processes spawn specific child binaries with known parent path patterns.
Florian Roth (Nextron Systems), Markus Neis, Huntrule TeamWindowsprocess_creationCritical367Free2020-02-01Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Alerts on Windows Audit-CVE EventID 1 entries from Microsoft-Windows-Audit-CVE provider indicating CveEventWrite activity.
Florian Roth (Nextron Systems), Zach Mathis, Huntrule TeamWindowsapplicationCritical412Free2020-01-15Citrix NetScaler CVE-2019-19781 Attempted Exploitation via Web Requests
Flags suspicious NetScaler HTTP URIs containing traversal-style /vpns/ portal script or config file references.
Arnim Rupp, Florian Roth, Huntrule Team—webserverCritical236Free2020-01-02Windows Registry Access to WCESERVICE Start Key
Detects registry activity targeting the WCE service Start configuration in Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical252Free2019-12-31Windows Process Execution of Windows Credential Editor (WCE) Executables
Flags execution of Windows Credential Editor (WCE.exe/WCE64.exe) using image name endings and known imphash values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical285Free2019-12-31Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Flags proxy requests with Base64-like URI characters plus '/images/' and '.avi' patterns consistent with Ursnif C2.
Thomas Patzke, Huntrule Team—proxyCritical51Free2019-12-19Windows CVE-2019-1388 UAC Consent to Internet Explorer Execution as LOCAL_SYSTEM
Flags UAC consent.exe launching iexplore.exe running as SYSTEM, consistent with CVE-2019-1388 exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical197Free2019-11-20Webserver CVE-2019-11510 Exploitation Attempt via Guacamole URI
Alerts on web requests with a Guacamole-related URI query pattern associated with a Pulse Secure CVE-2019-11510 exploitation attempt.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical149Free2019-11-18Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Flags PowerShell ScriptBlockText that combines Empire process-control indicators with dnscat DNS tunneling commands.
Alina Stepchenkova, Group-IB, oscd.community, Huntrule TeamWindowsps_scriptCritical71Free2019-11-01Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Alerts on Windows named pipe creations matching credential dumping tool pipe names.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowspipe_createdCritical375Free2019-11-01Windows process creation: Suspicious Dtrack RAT ping and network recon commands
Alerts on Windows command-line reconnaissance patterns resembling Dtrack RAT activity.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical82Free2019-10-30Linux sudo CVE-2019-14287 exploit attempt via unusual USER strings
Alerts on sudo events with USER values matching patterns linked to CVE-2019-14287 exploit attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsudoCritical112Free2019-10-15Linux auditd: Webshell Remote Command Execution via execve/execveat (euid=33)
Alerts on execve/execveat executions by the web server user, consistent with potential webshell command execution.
Ilyas Ochkov, Beyu Denis, oscd.community, Huntrule TeamLinuxauditdCritical212Free2019-10-12Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical111Free2019-10-11Windows Process Activity Indicative of QBot (WinRAR to wscript, ping/type, regsvr32)
Alerts on Windows process creation consistent with QBot-like script execution chains from WinRAR and regsvr32/tmp staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical291Free2019-10-01