Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Prefetch File Deletion via .pf File Removal
Flags deletion of .pf files in \\Windows\\Prefetch, a possible attempt to remove execution artifacts.
Cedric MAURUGEON, Huntrule TeamWindowsfile_deleteHigh174Free2021-09-29Windows DLL Hijacking via Forced Load of C:\Windows\ADFS\version.dll
Alert on loading C:\Windows\ADFS\version.dll, a DLL hijacking indicator consistent with the FoggyWeb technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadCritical463Free2021-09-27Web Path Traversal Exploitation Attempts via Encoded Traversal in URL Query
Alerts on web requests with URL query path traversal patterns targeting /etc/ and other sensitive filesystem paths.
Subhash Popuri (@pbssubhash), Florian Roth (Nextron Systems), Thurein Oo, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverMedium111Free2021-09-25Windows Process Memory Dump Using RdrLeakDiag.exe (/memdmp|fullmemdmp)
Alerts on Windows executions of rdrleakdiag.exe that request full or targeted memory dumps via /memdmp or /fullmemdmp.
Cedric MAURUGEON, Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4610Free2021-09-24Clipboard Data Collection via xclip (auditd Linux EXECVE)
Alerts on xclip command lines that request clipboard/clip selection output (-o) on Linux systems monitored by auditd.
Pawel Mazur, Huntrule TeamLinuxauditdLow123Free2021-09-24VMware vCenter Server file upload exploitation attempt for CVE-2021-22005 via POST telemetry endpoint
Identifies POST requests targeting a vCenter telemetry upload endpoint consistent with CVE-2021-22005 exploitation attempts.
Sittikorn S, Huntrule Team—webserverHigh82Free2021-09-24AWS CloudTrail: Lambda Function Updated with New Layer Attached
Flags CloudTrail UpdateFunctionConfiguration calls that attach Lambda layers to an existing function.
Austin Songer, Huntrule TeamAwscloudtrailLow142Free2021-09-23AWS CloudTrail Alert for Suspicious SAML Role Assumption and SAML Provider Updates
Flags CloudTrail activity involving SAML provider updates plus SAML role assumptions in AWS, which can enable backdoor access.
Austin Songer, Huntrule TeamAwscloudtrailMedium325Free2021-09-22PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsps_scriptHigh163Free2021-09-21Linux Import Tool Image Capture via execve with -window root and .png/.jpg output
Flags Linux ImageMagick import executions likely used for desktop screenshot capture to PNG/JPG outputs or root window.
Pawel Mazur, Huntrule TeamLinuxauditdLow1710Free2021-09-21Okta MFA Deactivation or Full Factor Reset Event Detection
Flags Okta events indicating MFA deactivation or reset_all actions by a user or actor.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium387Free2021-09-21Azure Activity Logs: New CloudShell Created via Microsoft.Portal Consoles Write
Alerts on Azure portal activity indicating a Cloud Shell console was created.
Austin Songer, Huntrule TeamAzureactivitylogsMedium451Free2021-09-21Windows: Xwizard.exe Execution from Non-Default Directory
Alerts when Xwizard.exe starts from an unexpected Windows path, indicating potential misuse or side-loading.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh455Free2021-09-20Detect suspicious AD SelfService web requests targeting report generation and API endpoints
Flags web requests with URL query strings targeting known ADSelfService exploitation paths for CVE-2021-40539.
Tobias Michalski (Nextron Systems), Max Altgelt (Nextron Systems), Huntrule Team—webserverHigh60Free2021-09-20Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Alert on HTTP 200 POST /wsman with no Authorization header and a non-empty body in Zeek logs, consistent with OMIGOD unauthenticated RCE attempts.
Nate Guagenti (neu5ron), Huntrule TeamZeekhttpHigh296Free2021-09-20