Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,321 rules
Potential CVE-2021-26084 Confluence OGNL RCE Exploitation Attempt via POST
Flags successful POST requests consistent with OGNL injection attempts targeting Confluence page variable endpoints tied to CVE-2021-26084.
Sittikorn S, Nuttakorn T, Huntrule Team—webserverHigh81Free2022-12-13Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.
frack113, Huntrule TeamWindowsregistry_setHigh143Free2022-12-11Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Identifies uncommon setres.exe children matching '\choice' while excluding System32/SysWOW64 choice.exe.
"@gott_cyber, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh172Free2022-12-11Windows Privilege Escalation via mklink Symlink Between cmd.exe and osk.exe
Alerts on mklink creating a symlink between osk.exe and cmd.exe, enabling potential login-screen privilege escalation.
frack113, Huntrule TeamWindowsprocess_creationHigh4410Free2022-12-11Windows Image Load of Specific System DLLs Not Normally Present in System Directories
Alerts on image load events for specific system-path DLLs with unexpected “phantom” DLL names on Windows.
Nasreddine Bencherchali (Nextron Systems), SBousseaden, Huntrule TeamWindowsimage_loadHigh131Free2022-12-09Windows Registry: LSASS Full Dump via WER LocalDumps DumpType=2
Flags registry changes enabling LSASS full memory dumps by setting WER LocalDumps DumpType to 0x2.
"@pbssubhash, Huntrule Team"Windowsregistry_setHigh252Free2022-12-08Windows: LSASS Dump (.dmp) Files in CrashDumps Folder
Alerts when an lsass.exe dump (.dmp) appears in the Windows CrashDumps directory under systemprofile.
"@pbssubhash, Huntrule Team"Windowsfile_eventHigh399Free2022-12-08Windows Application Error: LSASS (lsass.exe) Crashed (Event ID 1000)
Alerts on Application Error (Event ID 1000) entries where lsass.exe crashes, using Windows Application event telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh2010Free2022-12-07Windows windefend alerts on suspicious Windows Defender configuration changes (Disable* and SpyNet reporting)
Alerts on windefend Event 5007 when Defender configuration changes set features like anti-spyware, scanning, or SpyNet reporting to disabled values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh286Free2022-12-06Windows Windefend: Defender Restored File from Quarantine (EventID 1009)
Alerts on Windows Defender Windefend events indicating an item was restored from quarantine (Event ID 1009).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh91Free2022-12-06Windows Process Creation: Command Line Contains Emoji Characters
Alerts on Windows process executions whose command line includes emoji/symbol characters from a predefined list.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh2610Free2022-12-05Windows Process Command Line Contains Emoji Characters
Alerts when a Windows process command line includes emoji characters, which can be used to obscure activity or bypass naive detections.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh131Free2022-12-05Windows Process Creation: Command Line Contains Specific Emoji Characters
Alerts when a Windows process command line includes specific emoji Unicode characters that may be used for evasion or obfuscation.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh215Free2022-12-05Windows Process Creation Command-Line Contains Emoji Characters
Alerts on Windows executions whose command line includes emoji Unicode characters.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh309Free2022-12-05Windows Process Creation: Renamed Mavinject32/64.EXE Execution
Alerts on renamed executions of mavinject32.exe/mavinject64.exe based on OriginalFileName and image path.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh239Free2022-12-05