Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,321 rules
Windows: Execution of Htran/NATBypass HackTool Binaries or Tran/Slave CLI Flags
Detects Windows executions of htran.exe or lcx.exe and command lines containing -tran or -slave flags.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-12-27Potential CVE-2022-46169 Command Injection Probe Against Cacti Web Server
Alert on GET requests to Cacti polldata endpoints containing command-injection payload fragments tied to CVE-2022-46169.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh414Free2022-12-27Windows Process Execution: Suspicious AgentExecutor.exe PowerShell Launch with ExecutionPolicy Bypass
Detects AgentExecutor.exe command lines that trigger PowerShell script execution, including remediations and potentially bypassed ExecutionPolicy.
Nasreddine Bencherchali (Nextron Systems), memory-shards, Huntrule TeamWindowsprocess_creationHigh70Free2022-12-24Windows PowerShell Execution of AADInternals Cmdlets (process creation)
Flags PowerShell processes running AADInternals “-AADInt” cmdlets, indicating potential Azure AD/Office 365 administration or abuse.
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-12-23Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Alerts on Windows launches of Chromium-based browsers in headless + remote debugging mode targeting a user data directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-12-23Windows PowerShell Script Block Logging: AADInternals Cmdlets (Add-AADInt to Update-AADInt) Execution
Flags PowerShell script block execution that contains AADInternals cmdlet names (AADInt), indicating potential admin or abuse activity.
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptHigh103Free2022-12-23Windows: Explorer opened from cmd.exe/powershell using shell:MyComputerFolder shortcut
Flags explorer.exe opened for My Computer via shell:mycomputerfolder when started by cmd or PowerShell.
"@Kostastsale, Huntrule Team"Windowsprocess_creationHigh233Free2022-12-22Detect OWASSRF Webserver Exploitation Pattern Targeting PowerShell Backend
Alerts on successful POST requests to OWA URLs containing PowerShell backend indicators and Exchange-like probe user agents.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh111Free2022-12-22Potential OWASSRF Exploitation via OWA Proxy Requests (HTTP 200) - Exchange
Alerts on 200-status proxy POSTs targeting OWA-to-PowerShell backend paths with encoded user info markers.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh161Free2022-12-22Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access
Alerts on Linux user creation events that assign privileged UID/GID values like root, wheel, or sudo.
Pawel Mazur, Huntrule TeamLinux—High103Free2022-12-21Windows Registry Set Detection of Suspicious Environment Variable Commands
Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh297Free2022-12-20Windows Office Binary Execution with Renamed Image Path
Alerts when Office apps are executed under renamed or unexpected image paths, helping catch stealthy masquerading on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-12-20Windows SQLite CLI Querying Chromium Browser Profile Databases
Alerts when SQLite CLI is used to query Chromium-based browser profile databases containing logins, cookies, or history.
TropChaud, Huntrule TeamWindowsprocess_creationHigh208Free2022-12-19Windows DLL Sideloading via comctl32.dll in .local directories
Alerts on comctl32.dll loaded from System32 .local folders, consistent with Windows DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Subhash Popuri (@pbssubhash), Huntrule TeamWindowsimage_loadHigh4310Free2022-12-16Windows File Events: Suspicious .exe.local Path With comctl32.dll in System32
Detects System32 *.exe.local entries that reference comctl32.dll, consistent with DLL sideloading behavior.
Nasreddine Bencherchali (Nextron Systems), Subhash P (@pbssubhash), Huntrule TeamWindowsfile_eventHigh161Free2022-12-16