Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,357 rules
Windows File Events Indicative of SlashAndGrab ScreenConnect Post-Exploitation
Alerts on Windows file activity writing known SlashAndGrab-related ScreenConnect artifact paths and executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh193Free2024-02-23Windows DNS Queries to Known DPRK C2 Domains
Flags Windows DNS queries for specific DPRK-attributed C2 domain names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryHigh93Free2024-02-20Proxy Detection: Cobalt Strike Malleable C2 Profile HTTP URI/User-Agent/Method Patterns
Flags proxy HTTP requests whose URI, method, User-Agent, host, and cookie fragments match known Cobalt Strike malleable profile patterns.
Markus Neis, Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh3610Free2024-02-15FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching
Flags FortiOS sslvpnd activity containing known CVE-2022-42475 artifact paths from file-related events.
Nasreddine Bencherchali (Nextron Systems), Nilaa Maharjan, Douglasrose75, Huntrule TeamFortiossslvpndHigh255Free2024-02-08Windows iexpress.exe Creates Self-Extracting Binaries Using SED Files From Suspicious Paths
Flags suspicious use of Windows iexpress.exe to create self-extracting packages via SED directives from uncommon/temp paths.
Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh245Free2024-02-05Windows SharpMove (.NET) Execution via SharpMove.exe and Action Command-Line Flags
Alerts on SharpMove.exe process execution with command-line actions for DCOM, WMI VBS, and task scheduler.
Luca Di Bartolomeo (CrimpSec), Huntrule TeamWindowsprocess_creationHigh81Free2024-01-29Windows EDRSilencer Execution via Filtering Platform FilterName Change
Detects Filtering Platform custom outbound filter additions associated with potential EDRSilencer execution on Windows.
Thodoris Polyzos (@SmoothDeploy), Huntrule TeamWindowssecurityHigh418Free2024-01-29Windows Process Creation: SOAPHound Execution via AD Data Collection Command-Line Arguments
Flags SOAPHound execution on Windows by detecting command-line arguments used for Active Directory data collection.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh349Free2024-01-26Windows: Suspicious rundll32 Execution of Non-DLL Extension via Living-off-the-Land Parent Processes
Flags rundll32.exe executions from common script parents where the command line references known drop locations but lacks standard extensions.
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh172Free2024-01-26Windows process creation matching specific Peach Sandstorm command-line indicator
Alerts on Windows process creations whose command line contains a specific suspicious substring.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2024-01-15Windows: Detect renamed PingCastle binary execution via PE metadata and scanner command-line
Flags Windows processes that look like renamed PingCastle executables using PE original file names and PingCastle scanner/healthcheck arguments.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2024-01-11Windows PingCastle Execution From Suspicious Parent Processes
Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2024-01-11Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
Alerts on Windows loading of .cpl control panel items from uncommon paths instead of standard system directories.
Anish Bogati, Huntrule TeamWindowsimage_loadHigh284Free2024-01-09Windows WFP 5157: Connection Blocked for EDR Agent Binaries
Flags WFP blocked connections (EventID 5157) when an EDR/security agent binary is the blocked application.
"@gott_cyber, Huntrule Team"WindowssecurityHigh263Free2024-01-08Windows forfiles.exe Spawned cmd.exe from Non-System Location
Alerts on forfiles.exe running outside system paths and spawning cmd.exe with a forfiles-encoded command pattern.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsprocess_creationHigh438Free2024-01-05