Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,333 rules
Windows Process Creation Command-Line Indicator Matching 'uTYNkfKxHiZrx3KJ'
Triggers on Windows process creation events with command line containing 'uTYNkfKxHiZrx3KJ'.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-10-24Windows DLL Side-Loading via ProgramData Image Load Indicators (clip.exe and wsmprovhost.exe)
Flags ProgramData clip.exe or wsmprovhost.exe launching with suspicious DLL loads from ProgramData.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh93Free2023-10-24Windows File Creation Indicators Linked to Diamond Sleet Artifacts
Flags Windows file creations under \ProgramData matching specific payload component filename indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh71Free2023-10-24Windows DNS queries containing Diamond Sleet–related domains
Alerts on Windows DNS queries for QueryName values containing specific Diamond Sleet–related domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryHigh142Free2023-10-24Web exploitation attempts for CVE-2023-43261 causing info disclosure in Milesight routers
Alerts on successful GET requests for /lang/log/httpd.log in Milesight router web access logs, consistent with CVE-2023-43261 disclosure attempts.
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule Team—webserverHigh447Free2023-10-20Potential Information Disclosure via CVE-2023-43261 in Milesight Router Proxy Logs
Alerts on HTTP GET 200 responses for UR router log paths in proxy requests associated with CVE-2023-43261.
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule Team—proxyHigh153Free2023-10-20Cisco IOS XE Web UI Exploitation Indicators for CVE-2023-20198 via Syslog Login and Config Events
Matches Cisco IOS XE Web UI and web login success logs consistent with CVE-2023-20198 exploitation using specified admin/TAC usernames.
Lars B. P. Frydenskov (Trifork Security), Huntrule TeamCiscosyslogHigh2010Free2023-10-20Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsfile_eventHigh368Free2023-10-19Windows CertOC.exe Downloads File From IP-Based URL Using -GetCACAPS
Flags CertOC.exe executions using an IP-based URL in the command line with -GetCACAPS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2023-10-18Windows DLL Sideloading via ImageLoad of mscoRee/colorui/mapistub/HID payload DLLs
Alerts on Windows processes loading DLLs from targeted ProgramShared/ProgramData paths consistent with DLL sideloading.
Thurein Oo, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh161Free2023-10-18DarkGate-related Autoit3.exe execution with suspicious parent process (Windows)
Alerts on AutoIt3.exe execution when spawned from cmd.exe, KeyScramblerLogon.exe, or msiexec.exe, excluding common legitimate install paths.
Micah Babinski, Huntrule TeamWindowsprocess_creationHigh163Free2023-10-15Windows Process Creation: CoercedPotato.exe Execution via ExploitId Parameters
Flags Windows process creation for CoercedPotato.exe with --exploitId and known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh253Free2023-10-11Windows Named Pipe Creation with "\coerced\" PipeName Segment
Detects Windows named pipe creations where the pipe name contains the '\coerced\' pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdHigh132Free2023-10-11Windows: Suspicious HTA Startup Folder Creation by FoxitPDFReader.exe
Alerts on FoxitPDFReader.exe creating .hta files in the Startup Programs folder, which can indicate persistence.
Gregory, Huntrule TeamWindowsfile_eventHigh1810Free2023-10-11Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary
Flags Windows process executions that match renamed VS Code tunnel invocation patterns and related internal service startup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2023-09-28