Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,357 rules
OpenCanary MSSQL SQLAuth Login Attempt Detected (logtype 9001)
Flags MSSQL SQLAuth login attempts recorded by OpenCanary for credential-access style activity.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh152Free2024-03-08OpenCanary HTTPPROXY Login Attempt Shows Proxied Page Access
Alerts on OpenCanary HTTPPROXY events indicating a proxy request for another page.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh333Free2024-03-08OpenCanary: HTTP Form POST Login Attempt Observed on Port Service
Alerts on OpenCanary HTTP Form POST events indicating a login attempt to an exposed service.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh345Free2024-03-08OpenCanary application telemetry: HTTP GET requests received by monitored service
Alerts when OpenCanary logs an HTTP GET request to a monitored service endpoint.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh172Free2024-03-08OpenCanary Git Service: Git Clone Request Observed
Flags OpenCanary Git service logs showing a Git clone request, indicating possible repository access attempts.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh81Free2024-03-08OpenCanary FTP Login Attempt on Port 2000
Flags OpenCanary application events indicating an FTP login attempt on a monitored node.
Security Onion Solutions, Huntrule TeamOpencanaryapplicationHigh171Free2024-03-08GitHub Secret Scanning Disabled for Enterprise or Repository
Flags GitHub audit events that disable secret scanning for an enterprise or repository, reducing exposed secret detection.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditHigh407Free2024-03-07GitHub Audit: Secret Scanning Push Protection Disabled
Alerts on GitHub audit log events where secret scanning push protection is disabled for org, repo, or custom patterns.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditHigh461Free2024-03-07Windows Process Creation: rundll32 Shell32 Control_RunDLL Executes .CPL from User Temp
Detects rundll32 Shell32 Control_RunDLL launching a .CPL from user Temp, a stealthy execution path.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh92Free2024-03-07Windows ScreenConnect Service Web Shell Execution via cmd.exe or csc.exe
Alert on ScreenConnect.Service.exe spawning cmd.exe or csc.exe, consistent with potential web shell execution on Windows.
Jason Rathbun (Blackpoint Cyber), Huntrule TeamWindowsprocess_creationHigh121Free2024-02-26Bitbucket Audit: Secret Scanning Exempt Repository Added
Flags Bitbucket audit events where a repository is added as exempt from secret scanning.
Muhammad Faisal (@faisalusuf), Huntrule TeamBitbucketauditHigh214Free2024-02-25Bitbucket Audit: Full Data Export Triggered
Alerts when Bitbucket audit logging records a full data export being triggered.
Muhammad Faisal (@faisalusuf), Huntrule TeamBitbucketauditHigh151Free2024-02-25Windows Suspicious Wget.exe Downloads From IP to Common Staging Paths
Flags wget.exe on Windows downloading from an IP over HTTP and saving to common staging/user directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2024-02-23Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2024-02-23