Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,306 rules
Web Server GET Requests Containing SSTI Payload Strings (Server-Side Template Injection)
Flags GET requests containing SSTI probe strings in web access logs when the response is not 404.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh172Free2022-06-14Windows msdt.exe execution using PCWDiagnostic.xml answer file
Alerts on msdt.exe launched with PCWDiagnostic.xml and an answer-file argument, excluding cases from pcwrun.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2910Free2022-06-13Windows: Indirect execution of pcwrun.exe using path traversal-style command line content
Detects pcwrun.exe spawning with '../' in the command line, indicating potential indirect execution abuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-06-13Windows Registry Custom File Open Handler Executes PowerShell
Alerts when a registry shell open handler is created to run PowerShell with -command.
CD_R0M_, Huntrule TeamWindowsregistry_setHigh112Free2022-06-11Windows Process: Notepad++ GUP (GUP.exe) Download Execution via -unzipTo and URL
Detects Notepad++ GUP.exe downloading over HTTP initiated by a non-Notepad++ parent process.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh256Free2022-06-10Microsoft BITS Proxy Requests to Uncommon Server IP Hosts
Identifies Microsoft BITS proxy connections where the destination host ends with a single-digit, indicating uncommon IP-style addressing.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh93Free2022-06-10Windows: Adplus.exe Execution with Memory Dump and Command Options
Alerts on Windows executions of Adplus.exe with memory-dump and inline command parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-06-09Windows: ISO Image Opened by Archiver Utilities (WinRAR/7-Zip/PeaZIP)
Alerts when WinRAR/7-Zip/PeaZIP spawns ISO image tools, a pattern consistent with archive-delivered ISO payloads.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh103Free2022-06-07Detect DNS Queries to OAST Callback and Interaction Service Domains
Detects DNS lookups to common OAST/callback domains that may indicate SSRF-style or blind vulnerability validation.
Florian Roth (Nextron Systems), Matt Kelly (list of domains), Huntrule TeamNetworkdnsHigh171Free2022-06-07Windows Process Creation: Renamed Plink (plink.exe) with SSH Port Forwarding Flags
Alerts on renamed Plink executions using SSH port forwarding flags in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh359Free2022-06-06Webserver: Suspicious Windows Path Strings in URI Query
Alerts when a web URI query contains encoded or plain Windows path strings indicative of possible exfiltration or webshell behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebwebserverHigh121Free2022-06-06Windows: ManageEngine SupportCenter Plus msiexec.exe Dropped in bin (CVE-2021-44077 POC)
Alerts on msiexec.exe being created in the SupportCenterPlus bin folder on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh327Free2022-06-06Windows Office Startup Folder File Creation with Uncommon Extension
Detects unusual-extension files created in Word/Excel startup folders on Windows, potentially supporting automatic Office loading.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh305Free2022-06-05Java Payload Indicators in Web Server Logs
Alerts when web access logs contain Java payload-like strings indicating possible injection or runtime execution attempts.
frack113, Harjot Singh, "@cyb3rjy0t" (update), Huntrule TeamWebwebserverHigh142Free2022-06-04Windows Process Creation: Renamed msdt.exe Execution
Flags Windows process creation where OriginalFileName is msdt.exe and the executable appears to be a renamed copy.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh294Free2022-06-03