Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,333 rules
Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS
Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh383Free2023-11-09Windows: Detect SysAid user.exe Loader Execution by Filename and SHA256 Hash
Flags execution of a specific SysAid-hosted Windows binary when the process image path and SHA256 match.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2023-11-09Windows Process Execution for PowerShell Cobalt Strike Download via Hidden IEX
Flags PowerShell command lines that use IEX and hidden downloadstring to fetch a Cobalt Strike payload.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2023-11-09Windows PowerShell script launcher matching SysAidServer Tomcat paths
Flags PowerShell script block text tied to SysAid Tomcat webapp paths and user.exe staging/launch actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2023-11-09PowerShell Script Evidence Eraser Searching for cleanLL and usersfiles.war
Identifies PowerShell script blocks containing evidence-cleanup indicators and a repeating while(1) loop.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh407Free2023-11-09Windows PowerShell Script File Creation: SysAidServer Webapp User/User.exe Indicators
Detects creation of specific SysAidServer Tomcat webapp files indicative of PowerShell script staging on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh334Free2023-11-09F5 BIG-IP Webserver RCE exploitation attempts via POST to /mgmt/tm/util/bash
Alerts on POST requests to /mgmt/tm/util/bash containing tmui Control/form parameters consistent with CVE-2023-46747 exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh439Free2023-11-08F5 BIG-IP Proxy: Detect POST requests exploiting CVE-2023-46747 via /mgmt/tm/util/bash
Alerts on POST requests containing /mgmt/tm/util/bash plus TMUI control/user-create form parameters indicative of CVE-2023-46747 exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh112Free2023-11-08Windows Registry: Disabling Antivirus Filter Driver on Dev Drive via FltmgrDevDriveAllowAntivirusFilter
Detects registry changes disabling antivirus minifilter inspection on a Dev Drive by setting the allow setting to 0x0.
"@kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsregistry_setHigh333Free2023-11-05Windows image load and execution of unsigned Thor scanner (thor.exe/thor64.exe)
Alerts on thor.exe/thor64.exe image loads on Windows where the Authenticode signature is missing or not from Nextron Systems.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh469Free2023-10-29Windows Process Creation: rundll32 Spawns Pikabot-Like Hollowing Binaries
Alerts when rundll32.exe spawns specific Windows binaries in patterns consistent with potential process hollowing.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationHigh3710Free2023-10-27Windows Process Creation Signals for Pikabot System Discovery
Flags process-launch discovery commands (ipconfig/netstat/whoami) under rundll32 and Search host parent processes on Windows.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationHigh203Free2023-10-27Windows file creation of code_tunnel.json outside Code/VsCode executables
Alerts on creation of code_tunnel.json on Windows when it isn’t created by typical VS Code binaries.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh151Free2023-10-25Windows File Creation: inetmgr.exe in \Windows\ADFS\bg\ Path
Alerts on creation of \Windows\ADFS\bg\inetmgr.exe in Windows file events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh386Free2023-10-24Windows Registry Events: Scheduled Task Creation via TaskCache Tree Key
Flags registry activity creating TaskCache Tree entries tied to TeamCity settings UI during exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh162Free2023-10-24