Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Unusual Process Tree for wab.exe and wabmig.exe
Alert on abnormal parent/child process relationships involving wab.exe and wabmig.exe in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh202Free2022-08-12Windows Process Creation: wab.exe or wabmig.exe Run from Non-Default Paths
Alerts when wab.exe or wabmig.exe run from unexpected directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh198Free2022-08-12Windows: User Added to Local Administrators Group via Net or Add-LocalGroupMember
Flags Windows command lines that add a user to the local administrators group via net.exe or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium465Free2022-08-12Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-08-12Windows file write events where executables save files with suspicious script/binary extensions
Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2022-08-12Windows Malicious iphlpapi.dll Dropped in OneDrive/Teams AppData Directory
Flags creation of iphlpapi.dll in the Microsoft AppData area used by OneDrive/Teams, consistent with DLL sideloading attempts.
frack113, Huntrule TeamWindowsfile_eventHigh121Free2022-08-12Windows File Creation Time Altered to a Previous Year
Alerts on Windows events where a file’s creation time is altered to a different year, excluding common benign system/update tooling.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_changeLow90Free2022-08-12Webserver POST to SAAS/jersey manager API migrate tenant (Workspace ONE Access RCE pattern)
Alerts on POST requests to the Workspace ONE Access tenant migration API endpoint associated with CVE-2022-31659.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverMedium141Free2022-08-12Webserver URI Probe for Workspace ONE Access Auth Bypass Attempt (CVE-2022-31656)
Alerts on webserver requests to Workspace ONE Access containing a URI query pattern linked to CVE-2022-31656 exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh239Free2022-08-12Windows Service Installation of AnyDesk Software (Service Control Manager 7045)
Flags Windows service creation where AnyDesk appears in the service name and ImagePath via SCM Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssystemMedium353Free2022-08-11Azure Audit Logs: Privileged Account Creation via Admin Role Assignment
Flags successful events where a user is added and added to a role, indicating new admin account creation in Azure.
Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Tim Shelton, Huntrule TeamAzureauditlogsMedium141Free2022-08-11Azure AD Account Created and Deleted Shortly After Creation (Audit Logs)
Identifies successful Azure user creation and deletion in quick succession, consistent with short-lived account activity.
Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1', Tim Shelton, Huntrule TeamAzureauditlogsHigh172Free2022-08-11Windows Registry: Change to Services\WinSock2\Parameters\AutodialDLL for DLL Persistence
Alerts on registry changes to AutodialDLL under WinSock2 parameters that may enable DLL-based persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh461Free2022-08-10Windows Registry App Paths Default Property Change Using Suspicious Values
Alerts on Windows App Paths registry edits to (Default)/Path with suspicious binaries, scripts, or temp/public locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2022-08-10Windows Startup Folder File Creation with Suspicious Script/Executable Extensions
Alerts on creation of startup-folder files with script/executable extensions commonly used for logon persistence on Windows.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh314Free2022-08-10