Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,359 rules
Linux: Suspicious curl/wget Download to /tmp or /dev/shm Followed by sh -c Execution
Flags curl/wget retrieving content into /tmp or /dev/shm followed by immediate sh -c execution on Linux.
Aayush Gupta, Huntrule TeamLinuxprocess_creationHigh212Free2025-06-17Windows Process Creation: Possible CVE-2025-33053 WebDAV RCE via utility search-order manipulation
Flags suspicious child execution from WebDAV/UNC paths initiated by iediagcmd.exe or CustomShellHost.exe, consistent with CVE-2025-33053 exploitation.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh235Free2025-06-13Windows Process Access: Suspicious WebDAV target execution via iediagcmd.exe or CustomShellHost.exe (CVE-2025-33053)
Alerts when iediagcmd.exe or CustomShellHost.exe access WebDAV-hosted executables consistent with a potential RCE attempt.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh338Free2025-06-13Windows Process Creation: SharpSuccessor.exe Execution with Impersonation Parameters
Alerts on SharpSuccessor.exe command-line patterns indicative of Windows privilege escalation attempts.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2025-06-06Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
PowerShell spawning that uses WindowsInstaller.Installer COM with obfuscated strings to call InstallProduct and suppress UI.
Meroujan Antonyan (vx3r), Huntrule TeamWindowsprocess_creationHigh181Free2025-05-27Linux: Disable ASLR via personality syscall or sysctl/randomize_va_space changes
Flags Linux events where ASLR is disabled using the personality syscall or sysctl setting kernel.randomize_va_space=0.
Milad Cheraghi, Huntrule TeamLinuxauditdHigh162Free2025-05-26Windows reg.exe Registry Save/Export of Third-Party Credential Paths
Alerts on reg.exe save/export commands targeting registry keys tied to third-party credential data.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh232Free2025-05-22Zeek HTTP: Suspicious User-Agent Containing "katz-ontop"
Alerts on Zeek HTTP sessions whose User-Agent includes "katz-ontop", a potential malware indicator.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamZeekhttpHigh112Free2025-05-22DNS Queries to Katz Stealer–Associated Domains (Network)
Alerts on DNS queries for domains associated with Katz Stealer.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—dnsHigh374Free2025-05-22Windows DLL Load Indicators for Katz Stealer 2025 Variants
Alerts on Windows image loads of DLLs with Katz Stealer-associated names/paths.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadHigh373Free2025-05-22Windows DNS Queries to Katz Stealer-Related Domains
Alerts on Windows DNS queries to domains associated with Katz Stealer malware infrastructure.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsdns_queryHigh345Free2025-05-22Windows RMM Tool MeshAgent Execution with Renamed MeshServiceName
Identifies renamed MeshAgent executions on Windows by matching --meshServiceName with OriginalFileName containing meshagent.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamWindowsprocess_creationHigh171Free2025-05-19Windows Impacket-Pattern File Creation: sessionresume_[a-zA-Z]{8} Indicator
Flags Windows file creations of filenames matching Impacket sessionresume pattern ('sessionresume_<8 letters>').
The DFIR Report, IrishDeath, Huntrule TeamWindowsfile_eventHigh172Free2025-05-19macOS Process Creation: MeshAgent renamed execution via --meshServiceName
Identifies macOS executions of MeshAgent instances that include --meshServiceName, indicating potential renamed remote access tooling.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamMacosprocess_creationHigh214Free2025-05-19Webserver POST Uploads Java Web Shell Files in SAP NetViewer
Alerts on POST requests to /irj/ endpoints uploading Java extension files with octet-stream content type.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverHigh173Free2025-05-14