Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux Commands Clearing or Removing /var/log/syslog
Flags Linux activity that clears, deletes, or redirects /var/log/syslog, a likely attempt to impair logging.
Max Altgelt (Nextron Systems), Huntrule TeamLinux—High123Free2021-09-10Zoho ManageEngine ADSelfService Plus CVE-2021-40539 REST API exploit URL access (Web)
Flags web requests targeting ADSelfService Plus REST API paths linked to CVE-2021-40539 authentication bypass.
Sittikorn S, Nuttakorn Tungpoonsup, Huntrule Team—webserverCritical110Free2021-09-10Windows Winword.exe Creates INetCache .cab and .inf Files During CVE-2021-40444 Exploitation
Flags winword.exe writing CABs in INetCache or INF files in Temp consistent with CVE-2021-40444 exploitation.
Florian Roth (Nextron Systems), Sittikorn S, Huntrule TeamWindowsfile_eventHigh161Free2021-09-10Linux auditd: Unzip files extracted from JPG/PNG images
Alerts when unzip is run against image files (.jpg/.png), consistent with extracting hidden data from steganographic containers.
Pawel Mazur, Huntrule TeamLinuxauditdLow102Free2021-09-09Linux auditd: cat appends ZIP data to image files
Alerts when cat is used to handle .jpg/.png with an associated .zip argument, consistent with hiding ZIP data in images.
Pawel Mazur, Huntrule TeamLinuxauditdLow101Free2021-09-09Windows Process Execution of control.exe Spawned by Office Apps Matching CVE-2021-40444 Pattern
Alerts when control.exe is launched from Office apps with suspicious DLL-related command lines, consistent with CVE-2021-40444 exploitation attempts.
Florian Roth (Nextron Systems), @neonprimetime, Huntrule TeamWindowsprocess_creationHigh122Free2021-09-08Windows Process Creation: Atlassian Confluence Java Spawns Suspicious Utility Child Processes (CVE-2021-26084)
Flags suspicious child processes spawned by Confluence’s Java on Windows, consistent with attempted CVE-2021-26084 exploitation.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh131Free2021-09-08Windows Image Load of clfsw32.dll by svchost.exe indicating PRIVATELOG usage
Alert on svchost.exe loading clfsw32.dll, a rarely observed Windows image load pattern consistent with PRIVATELOG.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2021-09-07Linux auditd: Hidden file or directory creation via leading-dot paths in execve
Alerts on Linux process executions creating or modifying dot-prefixed (hidden) files/directories.
Pawel Mazur, Huntrule TeamLinuxauditdLow152Free2021-09-06Azure AD Domain Federation Settings Modified via Audit Logs
Alerts when federation settings on an Azure AD domain are modified, indicating potential identity trust tampering.
Austin Songer, Huntrule TeamAzureauditlogsMedium143Free2021-09-06Linux Audio Capture via arecord and ecasound (auditd execve and memfd_create)
Detects Linux execution of arecord for audio capture and ecasound using memfd_create for in-memory data handling.
Pawel Mazur, Milad Cheraghi, Huntrule TeamLinuxauditdLow377Free2021-09-04Linux auditd System Information Discovery via uname, uptime, lsmod, hostname, env, and release file reads
Triggers on auditd events showing host enumeration commands and system identity file access on Linux.
Pawel Mazur, Huntrule TeamLinuxauditdLow173Free2021-09-03Azure Audit Logs: Service Principal Removed via Remove service principal
Flags Azure audit log events where a service principal is removed from Entra ID.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium236Free2021-09-03Azure Audit Logs: Owner Removed From Application or Service Principal
Alerts on Azure audit log activity indicating an owner was removed from an application or service principal.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium163Free2021-09-03Azure Audit Logs: Device No Longer Managed or Compliant
Alerts on Azure device audits indicating the device is no longer managed or compliant.
Austin Songer @austinsonger, Huntrule TeamAzureauditlogsMedium175Free2021-09-03