Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,329 rules
Windows Code Integrity: Revoked Kernel Driver Loaded (Event 3021/3022)
Alerts when Windows Code Integrity reports a revoked kernel driver/module loaded (including debugger-allowed cases) via Event IDs 3021/3022.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh179Free2023-06-06Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Flags Code Integrity Operational events where Windows blocks loading a revoked (untrusted) driver certificate.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh147Free2023-06-06Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
Alerts on Windows Code Integrity Event ID 3104 when a disallowed file is blocked for protected processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh113Free2023-06-06Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript
Alerts on suspicious renamed AutoIt2/AutoIt3 execution based on command-line parameters plus known hashes and original file names.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2023-06-04Webserver GET Requests to MOVEit Human2.aspx Paths Indicative of CVE-2023-34362 Web Shell Attempts
Alerts on GET requests to human2.aspx/_human2.aspx paths associated with MOVEit CVE-2023-34362 exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh459Free2023-06-03Linux: Shell Execution from /tmp by Parent Process
Alert when a /tmp parent process spawns a shell (bash/sh/zsh/etc.), indicating likely staging and command execution.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationHigh110Free2023-06-02Linux nohup Execution from /tmp
Flags Linux process executions using nohup with command lines referencing /tmp.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationHigh122Free2023-06-02Linux grep file discovery targeting GobRAT-specific filenames
Alerts on grep executions on Linux whose arguments contain specific malware-related file names for discovery.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationHigh274Free2023-06-02Windows DLL Sideloading via SmadHook32c.dll and SmadHook64c.dll Loads
Alerts on non-standard loads of SmadHook32c.dll/SmadHook64c.dll on Windows, consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh181Free2023-06-01Proxy Traffic to Operation Triangulation Domains Indicative of C2 Beaconing
Alerts on proxy requests to specific suspect C2-related domains by host substring match.
Florian Roth (Nextron Systems), Huntrule Team—proxyHigh162Free2023-06-01Suspicious DNS Queries to Operation Triangulation-Like Domains for C2 Beaconing
Detects DNS queries to known Operation Triangulation-related domains that may indicate C2 beaconing.
Florian Roth (Nextron Systems), Huntrule Team—dnsHigh91Free2023-06-01Windows File Activity Indicators of Potential MOVEit Transfer CVE-2023-34362 Exploitation
Finds MOVEit Transfer webroot file and ASP.NET compilation artifacts on Windows that may indicate CVE-2023-34362 exploitation.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh175Free2023-06-01Webserver: Potential CVE-2023-25717 Ruckus Wireless Admin Injection via Unauthenticated HTTP GET
Alerts on suspicious GET requests to Ruckus Wireless Admin login endpoints containing '$(' payload markers.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh72Free2023-05-30Windows regsvr32 Execution from Suspicious DLL Paths
Alerts on regsvr32 runs whose command line references a DLL in highly suspicious Windows directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-05-26Windows regsvr32 Execution of calc with /s flag
Alerts on regsvr32.exe runs using /s with a command line ending in calc.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh423Free2023-05-26