Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,358 rules
Windows CSharp Streamer RAT Potentially Loaded .NET Executable from Temp dat####.tmp
Identifies .NET executable image loads from a CSharp Streamer RAT-like Temp .tmp path pattern on Windows.
Luca Di Bartolomeo, Huntrule TeamWindowsimage_loadHigh402Free2024-06-22Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Alerts on initiated outbound connections from Windows hosts to LocaltoNet/.localtonet.com tunneling domains.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsnetwork_connectionHigh173Free2024-06-17Linux: Network connections initiated to LocaltoNet tunneling subdomains
Alerts when a Linux host initiates outbound connections to LocaltoNet (.localto.net/.localtonet.com) tunneling subdomains.
Andreas Braathen (mnemonic.io), Huntrule TeamLinuxnetwork_connectionHigh4810Free2024-06-17Windows: File Creation by mysqld.exe With Script/Executable Extensions
Alerts on file creation by mysqld.exe producing .bat/.exe/.ps1/.vbs and other executable or script file types on Windows.
Joseph Kamau, Huntrule TeamWindowsfile_eventHigh223Free2024-05-27Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh100Free2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh288Free2024-05-10Proxy WebDAV MiniRedir Drives Execution from External Shares
Alert on external WebDAV MiniRedir GET requests for executable-like file extensions that may lead to execution.
Ahmed Farouk, Huntrule TeamWebproxyHigh233Free2024-05-10Linux network connections to known malware callback ports
Alerts on initiated Linux outbound connections to specific known suspicious destination ports, excluding local/private IP ranges.
hasselj, Huntrule TeamLinuxnetwork_connectionHigh196Free2024-05-10Windows: Alert on Outbound Connections Initiated by dialer.exe (Microsoft Phone Dialer)
Alerts on outbound connections started by Windows dialer.exe, excluding common local and reserved IP ranges.
CertainlyP, Huntrule TeamWindowsnetwork_connectionHigh120Free2024-04-26Windows Registry Set: Custom Protocol Handler DLL for CLSID {026CC6D7-34B2-33D5-B551-CA31EB6CE345}
Alerts when a Windows registry entry for a specific custom protocol handler CLSID is set to a DLL.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh134Free2024-04-23Windows Process Creation: Forest Blizzard-related hashes and scheduled task activity
Detects suspicious Windows process execution tied to known hashes or schtasks/PowerShell command-line patterns used for staging and compression.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2024-04-23Windows File Creation: ProgramData Persistence Artifacts Matching
Alerts on Windows file creations in C:\ProgramData matching specific driver inf, .dll, and batch/script filename patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh192Free2024-04-23Suspicious Palo Alto GlobalProtect Session Unmarshal Path Traversal and Command Injection Attempts
Detects GlobalProtect logs with directory traversal/command injection-style indicators tied to CVE-2024-3400 behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamPaloaltoapplianceHigh151Free2024-04-18Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh529Free2024-04-15Linux sshd Spawns Root Shell Script Commands Suggesting CVE-2024-3094 Exploitation
Alerts on sshd spawning bash/sh one-liners as root, a potential indicator of CVE-2024-3094 style exploitation.
Arnim Rupp, Nasreddine Bencherchali, Thomas Patzke, Huntrule TeamLinuxprocess_creationHigh213Free2024-04-01