Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,327 rules
Windows Process Creation: Crassus Privilege Escalation Discovery Tool Execution
Identifies execution of the Crassus Windows privilege escalation discovery tool via process metadata.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh288Free2023-04-17Windows: Stracciatella.exe Process Execution Identification (SharpPick behavior)
Alerts on Windows process creation for Stracciatella.exe using PE metadata and known SHA256 hashes.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-04-17Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Flags Certipy.exe execution on Windows using PE metadata and Certipy-like AD CS command-line arguments.
pH-T (Nextron Systems), Sittikorn Sangrattanapitak, Huntrule TeamWindowsprocess_creationHigh319Free2023-04-17Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Identifies Windows processes running Certify.exe with AD certificate abuse-oriented command line arguments.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2023-04-17Windows: Unexpected Termination of Message Queuing (MSMQ) Service via SCM Event 7034
Flags Service Control Manager Event ID 7034 for unexpected termination of the Message Queuing (MSMQ) service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh241Free2023-04-14Windows Service Control Manager: Termination of Security-Critical Services With Error
Alerts on error-terminated Windows security and infrastructure services from Service Control Manager event 7023.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh182Free2023-04-14Windows: Suspicious subprocesses launched by mqsvc.exe consistent with CVE-2023-21554 exploitation
Alerts when mqsvc.exe spawns common scripting/utility executables often used for unauthorized execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh365Free2023-04-12Linux Process Creation: PHP CLI Inline Code Using fsockopen with -r
Alerts on Linux executions of php -r inline code that references fsockopen, consistent with outbound reverse-shell style socket creation.
"@d4ns4n_, Huntrule Team"Linuxprocess_creationHigh132Free2023-04-07Linux Perl Reverse Shell Execution via Perl -e and Socket/exec Patterns
Detects perl -e one-liners on Linux that include Perl Socket::INET reverse-shell code patterns and exec/connect logic.
"@d4ns4n_, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Linuxprocess_creationHigh171Free2023-04-07Linux netcat/ncat Execution with -e and Shell Invocation
Alerts on Linux executions of nc/ncat using -e that reference common shells, indicating potential reverse-shell setup.
"@d4ns4n_, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Linuxprocess_creationHigh308Free2023-04-07Okta Failed Login with Password-Like AlternateID Value
Alerts on Okta login_failed events with alternateId values that may contain password data, risking credential exposure in logs.
kelnage, Huntrule TeamOktaoktaHigh163Free2023-04-03Possible ICO C2 File Downloads via Proxy: Compromised 3CXDesktopApp
Flags proxy requests for 3CXDesktopApp icon storage URIs ending in .ico, indicating potential malicious payload downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh268Free2023-03-31Proxy Beaconing to 3CX-Related Domains Indicating Possible Compromise
Flags proxy requests to 3CX-related domains that may indicate C2 beaconing behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh3810Free2023-03-29Windows: Flag 3CXDesktopApp updater fetching a known compromised update URL
Alerts on 3CXDesktopApp updater.exe launched with update arguments pointing to a known compromised HTTP update path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh245Free2023-03-29Windows Process Creation: Suspicious Child Executables Spawned by 3CXDesktopApp.exe
Alerts on suspicious execution utilities spawned by 3CXDesktopApp.exe via Windows process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2023-03-29