Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Suspicious /dev/tcp Usage in Linux Shell Commands
Flags Linux shell commands containing suspicious /dev/tcp redirection and file descriptor constructs.
frack113, Huntrule TeamLinux—Medium405Free2021-12-10Webserver log detection of Log4j CVE-2021-44228 JNDI payloads in User-Agent, URI query, or Referer
Flags webserver requests with ${jndi:...} payloads in User-Agent, URI query, or Referer indicative of Log4Shell attempts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh285Free2021-12-10Webserver detection of Log4j RCE (CVE-2021-44228) JNDI injection patterns
Detects webserver traffic containing Log4Shell-style JNDI injection payload strings, excluding Nessus scan artifacts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh111Free2021-12-10Windows Process Creation: Suspicious Executable Image Extension
Flags Windows process creations where the executable image path ends with an unexpected extension, after filtering known benign cases.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium308Free2021-12-09Windows Process Creation: Executable Image Missing Absolute Path (Possible Process Ghosting)
Flags Windows process creation where the executable Image lacks an absolute path, potentially indicating process ghosting.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh321Free2021-12-09Grafana Web Path Traversal Exploitation (CVE-2021-43798) With 200 Responses
Alerts on Grafana web requests with traversal patterns in the URI query that return HTTP 200.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical3810Free2021-12-08Windows Process Creation: Suspicious Network Configuration and Discovery Commands
Alerts on Windows command-line usage of network configuration and discovery tools (ipconfig, netsh, arp, nbtstat, net config, route print).
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow193Free2021-12-07Windows netsh.exe Firewall Configuration Discovery (show firewall rule/state/name=all)
Flags netsh.exe commands used to enumerate Windows firewall rules and states via “show firewall … name=all”.
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsprocess_creationLow176Free2021-12-07Windows PowerShell Process Creation with DInjector Cradle Flags (/am51 and /password)
Identifies Dinject PowerShell cradle usage by matching command-line flags '/am51' and '/password' in Windows process creation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical4710Free2021-12-07Windows: Suspicious PowerShell Interactive History Files Created as SYSTEM
Alerts on creation of PowerShell interactive history/profile files under SYSTEM, signaling privileged PowerShell activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh114Free2021-12-07Windows: User Added to Local Remote Desktop Users Group via Net or PowerShell
Detects Windows command-line activity that adds a user to the local Remote Desktop Users group using net localgroup or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh302Free2021-12-06Windows: Network connections initiated to api.mega.co.nz or mega.nz
Identifies initiated Windows outbound connections to api.mega.co.nz/mega.nz for potential file-transfer staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionLow197Free2021-12-06Windows: Remote Network Share Writes to desktop.ini
Flags remote network-shared desktop.ini being written to with high-impact permissions in Windows Security logs.
Tim Shelton (HAWK.IO), Huntrule TeamWindowssecurityMedium3510Free2021-12-06Windows sc.exe Service Query Execution via Process Creation
Flags sc.exe executions with command lines containing " query", consistent with Windows service information discovery.
frack113, Huntrule TeamWindowsprocess_creationLow80Free2021-12-06Windows System Logs: Windows Update Client errors (connection, install, uninstall, revert, commit)
Alerts on Windows Update Client errors in System logs, including connection, install, uninstall, revert, and commit failures.
frack113, Huntrule TeamWindowssystemInformational198Free2021-12-04