Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Webserver User-Agent Identifies Known Recon and Scanning Tool Strings
Alerts on web requests with User-Agent values containing known recon/scanner tool identifiers.
Nasreddine Bencherchali (Nextron Systems), Tim Shelton, Huntrule TeamWebwebserverMedium103Free2022-07-19Azure App/Service Principal Assigned to Entra ID or Azure RBAC Roles (Audit Logs)
Finds Azure role assignments where an app/service principal is granted, eligible, or scoped membership via audit log messages.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsMedium174Free2022-07-19Azure Entra conditional access policy updated by non-approved actor
Alerts when an Azure Entra Conditional Access policy update occurs, indicating access control changes by an actor outside the approved set.
Corissa Koopmans, '@corissalea', Huntrule TeamAzureauditlogsMedium71Free2022-07-19Azure Entra Conditional Access Policy Deleted by Non-Approved Actor
Flags Azure audit log events where a conditional access policy is deleted.
Corissa Koopmans, '@corissalea', Huntrule TeamAzureauditlogsMedium359Free2022-07-19Weblog Detection of Apache Spark Shell Command Injection Payloads (?doAs=`)
Alerts on web requests containing "?doAs=`" that may indicate Spark shell command injection attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh112Free2022-07-19Rejetto HFS HTTP request RCE exploit pattern via null-byte search and script/command payloads
Detects Rejetto HFS HTTP requests with a crafted search parameter and command/script execution indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh278Free2022-07-19Windows UEFI Persistence: Detect wpbbin.exe Execution
Alerts on execution of C:\Windows\System32\wpbbin.exe, a potential indicator of UEFI persistence on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-07-18Windows UEFI Persistence Indicator: Creation of C:\Windows\System32\wpbbin.exe
Flags creation of C:\Windows\System32\wpbbin.exe, a potential UEFI persistence artifact.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh442Free2022-07-18Azure Conditional Access Policy Added by Non-approved Actor
Alerts on Azure audit log events indicating a Conditional Access policy was added.
Corissa Koopmans, '@corissalea', Huntrule TeamAzureauditlogsMedium123Free2022-07-18Windows Registry Fax Device Provider ImageName changed to load external DLL
Alerts when Fax Device Providers\ImageName registry values change in a way consistent with DLL-loading persistence.
frack113, Huntrule TeamWindowsregistry_setHigh103Free2022-07-17Windows Registry: User Account Changed for FAX Service
Flags registry changes that alter the FAX service’s associated user account on Windows.
frack113, Huntrule TeamWindowsregistry_setHigh245Free2022-07-17Windows UAC Bypass via iscsicpl.exe DLL Search Order Hijacking (iscsiexe.dll)
Detects iscsicpl.exe loading iscsiexe.dll from outside C:\Windows, consistent with UAC bypass DLL hijacking.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh412Free2022-07-17Windows System Process Loads DLL from Suspicious or Permissive Paths
Alerts when a Windows system process loads a DLL from permissive or suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium121Free2022-07-17Windows Process Creation: NTVDM (ntvdm.exe/csrstub.exe) Start for 16-bit App Compatibility
Flags creation of NTVDM-related processes (ntvdm.exe or csrstub.exe) used to run legacy 16-bit/DOS applications on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium153Free2022-07-16Windows Process Initiated Connections to Ngrok Domains
Alerts when a Windows process initiates an outbound connection to ngrok domain hostnames, which may indicate staging or C2 activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh122Free2022-07-16