Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,305 rules
Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Detects rundll32.exe launching davclnt.dll DavSetCookie with HTTP and spoolss/srvsvc pipe parameters associated with NTLM coercion.
Elastic (idea), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-05-04Linux: Detects Nimbuspwn-related exploit strings targeting CVE-2022-29799/CVE-2022-27800
Detects Linux keyword patterns suggesting Nimbuspwn-style traversal attempts via networkd-dispatcher error handling.
Bhabesh Raj, Huntrule TeamLinux—High349Free2022-05-04Windows Registry: Service configured with image path in suspicious public/temp folders
Detects Windows service ImagePath pointing to Users\Public, Perflogs, ADMIN$, or Temp based on registry_set events.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsregistry_setHigh141Free2022-05-02Windows: PrintBrm.exe ZIP extraction or creation via command-line parameters
Flags PrintBrm.exe executions that include '-f' and '.zip', consistent with ZIP creation or extraction behavior.
frack113, Huntrule TeamWindowsprocess_creationHigh132Free2022-05-02Windows svchost.exe RDP (3389) Connections to HTTP/HTTPS Ports 80 or 443
Alerts when svchost.exe initiates from TCP 3389 to destination ports 80 or 443, consistent with possible RDP tunneling over web ports.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh182Free2022-04-29Windows: Detect ngrok Traffic Forwarded to Local RDP Port via TerminalServices Logs
Detects suspicious ngrok usage that forwards to the local RDP port using Windows TerminalServices-LocalSessionManager EventID 21.
Florian Roth (Nextron Systems), Huntrule TeamWindowsterminalservices-localsessionmanagerHigh111Free2022-04-29Windows: rundll32.exe spawning explorer.exe child process (shell32.Control_RunDLL)
Alerts on rundll32.exe spawning explorer.exe, an uncommon child process pattern that may indicate stealthy execution via shell components.
elhoim, CD_ROM_, Huntrule TeamWindowsprocess_creationHigh142Free2022-04-27Windows Process Creation: KrbRelay.exe Kerberos Relay Tool Execution
Flags Windows process creation for KrbRelay.exe with Kerberos relaying-related command-line arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2022-04-27Windows Hacktool Execution via PE Metadata Company Field
Flags execution of Windows binaries with PE Company metadata set to "Cube0x0", even when renamed.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-04-27Windows UAC Bypass via Event Viewer RecentViews File Creation
Alerts on suspicious file events to Event Viewer RecentViews paths that may indicate a Windows UAC bypass attempt.
Antonio Cocomazzi (idea), Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh269Free2022-04-27Windows Successful Local Kerberos Logon to Built-in Administrator (Possible Privilege Escalation)
Alert on successful local (127.0.0.1) Kerberos logons targeting the built-in Administrator SID for potential privilege escalation.
Elastic, @SBousseaden, Huntrule TeamWindowssecurityHigh102Free2022-04-27Windows: Detect KrbRelayUp.exe HackTool Process Execution
Flags Windows process executions of KrbRelayUp.exe with relay/domain and SCM spawn command-line patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh359Free2022-04-26Windows Sysmon Application Popup Crash (Event ID 26)
Flags Application Popup events reporting sysmon64.exe/sysmon.exe “Application Error” (Event ID 26).
Tim Shelton, Huntrule TeamWindowssystemHigh104Free2022-04-26Windows: File Creation of Get-Variable.exe in PowerShell WindowsApps Path
Alerts on creation of Get-Variable.exe in Local\Microsoft\WindowsApps, a potential cmdlet-path hijack.
frack113, Huntrule TeamWindowsfile_eventHigh162Free2022-04-23Windows Remote Thread Created in KeePass.exe
Flags remote thread creation targeting KeePass.exe, a possible indicator of credential theft.
Timon Hackenjos, Huntrule TeamWindowscreate_remote_threadHigh93Free2022-04-22