Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry: Flag Print Driver Registry Paths for QMS 810 and mimikatz
Detects registry TargetObject entries containing QMS 810 or mimikatz-related printer driver names under Windows print environments.
Markus Neis, @markus_neis, Florian Roth, Huntrule TeamWindowsregistry_eventCritical209Free2021-07-04Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)
Flags Windows Print Spooler Event ID 316 entries containing UNIDRV/mimispool-related keywords indicative of CVE-2021-1675 exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprintservice-operationalCritical142Free2021-07-01Windows Suspicious DLL Deletion in Spooler Driver Folder (PrintNightmare/CVE-2021-1675)
Alerts when spoolsv.exe deletes a DLL from the Spooler driver folder path on Windows.
Bhabesh Raj, Huntrule TeamWindowsfile_deleteHigh231Free2021-07-01Antivirus detections of PrinterNightmare PoC file creation path on Windows
Alerts on antivirus events where filenames include the Windows spooler driver x64 directory path, excluding Symantec submission messages.
Sittikorn S, Nuttakorn T, Tim Shelton, Huntrule Team—antivirusCritical469Free2021-07-01Windows SMB Client Security: Rejected Guest Logon with Blank UserName
Flags rejected SMB guest/anonymous-style logons on Windows when the SMB username is blank.
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Huntrule TeamWindowssmbclient-securityMedium248Free2021-06-30Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Looks for Print Spooler plug-in/module load errors in Windows logs that may indicate CVE-2021-1675 exploitation attempts.
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Tim Shelton, Huntrule TeamWindowsprintservice-adminHigh351Free2021-06-30Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
Wojciech Lesicki, Huntrule TeamWindowsregistry_setHigh233Free2021-06-29AWS EC2: DisableEbsEncryptionByDefault API call to turn off default EBS encryption
Flags when EC2 default EBS encryption is disabled for the current AWS region via CloudTrail.
Sittikorn S, Huntrule TeamAwscloudtrailMedium285Free2021-06-29Pulse Connect Secure web exploitation attempts for CVE-2021-22893
Detects web requests to Pulse Connect Secure with URI query patterns consistent with CVE-2021-22893 exploitation attempts.
Sittikorn S, Huntrule Team—webserverHigh476Free2021-06-29Windows ImageLoad of DLL from spoolsv.exe spool drivers subfolders
Flags spoolsv.exe DLL loads originating from Print Spooler x64\3/x64\4 driver folders on Windows.
FPT.EagleEye, Thomas Patzke (improvements), Huntrule TeamWindowsimage_loadInformational317Free2021-06-29Windows File Events: PoC Filename Pattern for CVE-2021-1675 Spooler Exploitation
Flags Windows file events referencing a specific spooler driver path pattern associated with CVE-2021-1675 PoC activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical241Free2021-06-29Windows reg.exe Run Key Modification for Persistence via Process Creation
Alerts on reg.exe commands that add values to Windows Run registry keys, a common persistence technique.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium130Free2021-06-28AWS CloudTrail: Security Hub findings evasion via finding updates or deletions
Identifies Security Hub finding and insight modifications (update or delete) that may impair detection results.
Sittikorn S, Huntrule TeamAwscloudtrailHigh192Free2021-06-28Windows Process Creation: WMIC.exe ActiveScriptEventConsumer Creation Attempt
Alerts on WMIC.exe command lines attempting to create an ActiveScriptEventConsumer for event-driven script execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh504Free2021-06-25Zeek x509: Default Cobalt Strike certificate serial observed in HTTPS traffic
Flags Zeek x509 certificates used in HTTPS when the certificate serial matches a known default Cobalt Strike value.
Bhabesh Raj, Huntrule TeamZeekx509High192Free2021-06-23