Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,324 rules
Windows PowerShell Module Execution Matches Known Offensive PoshModule Script Names
Alerts on Windows PowerShell module executions where the script context matches known offensive PowerShell script/module names.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_moduleHigh415Free2023-01-23Windows: Detect Aruba Netsvc DLL Search Order Hijacking via arubanetsvc.exe Loaded DLLs
Flags arubanetsvc.exe loading targeted DLLs outside standard system paths, suggesting possible DLL search order hijacking.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh374Free2023-01-22Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Detects rundll32 executions that reference DLLs stored in Alternate Data Streams via ADS-style paths.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamWindowsprocess_creationHigh103Free2023-01-21Windows PsExec Remote Execution Creates PSEXEC-*.key File Artefact
Alerts on creation of PsExec key files in C:\Windows\PSEXEC-*.key, indicating remote execution activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3010Free2023-01-21Windows Process Creation: svchost DHCPServer RCE Exploitation Attempt
Alerts on svchost.exe running as Network Service with -k DHCPServer, suggesting a potential pre-auth Windows RCE attempt.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh262Free2023-01-21Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Alerts on PowerShell module payloads containing commandlet/function names from known malicious exploitation and post-exploitation frameworks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_moduleHigh132Free2023-01-20Detect CentOS Web Panel POST login reverse-shell RCE attempts (CVE-2022-44877)
Alert on POST requests to CentOS Web Panel login that contain command-execution and reverse-shell style query parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh221Free2023-01-20Windows: driverquery.exe Usage for Installed Driver Recon
Alerts when driverquery.exe (drvqry.exe) is launched by script-based parent processes to enumerate installed drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2023-01-19Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
Flags successful Windows SMB (LogonType 3) logons from non-private, non-local source IP addresses.
Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity), Huntrule TeamWindowssecurityHigh60Free2023-01-19Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-01-18Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Alerts on Windows Defender Firewall configurations where all rules are deleted (Event 2033/2059), signaling potential defense impairment.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asHigh163Free2023-01-17Windows DNS Client: DNS query for anonfiles.com domain
Alerts when Windows DNS client logs show a DNS query containing .anonfiles.com.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientHigh171Free2023-01-16Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
Flags registry writes that reference an Excel XLL add-in via a '/R ' command under Excel Options.
frack113, Huntrule TeamWindowsregistry_setHigh378Free2023-01-15Windows Registry: DisableRestrictedAdmin Value Tampering to Change Restricted Admin Mode
Flags registry modifications to DisableRestrictedAdmin that change Restricted Admin mode settings.
frack113, Huntrule TeamWindowsregistry_setHigh132Free2023-01-13Windows Process Creation: Registry Tampering of DisableRestrictedAdmin in Lsa Key
Alerts when a process command line references LSA DisableRestrictedAdmin to change RestrictedAdmin behavior via the registry.
frack113, Huntrule TeamWindowsprocess_creationHigh417Free2023-01-13