Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows DNS Queries for userstorage.mega.co.nz Subdomain
Alerts on DNS queries referencing MEGA userstorage subdomains from Windows hosts.
Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsdns_queryMedium122Free2021-05-26Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssystemCritical245Free2021-05-26Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssecurityHigh103Free2021-05-26Windows Named Pipe Creation Matching Cobalt Strike Default Pipe Prefixes
Flags Windows named pipe creation where PipeName matches known Cobalt Strike default pipe prefixes.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowspipe_createdCritical131Free2021-05-25Linux PAM TTY Audit Enabling via /etc/pam.d Modification
Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.
Pawel Mazur, Huntrule TeamLinuxauditdHigh152Free2021-05-24Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Flags indicating PsExec/PAExec-style execution as LOCAL SYSTEM using cmd/powershell/pwsh in process command lines.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4110Free2021-05-22Windows Process Creation: Renamed PAExec Application Execution
Flags Windows executions of a renamed PAExec binary using process metadata and known IMPHASH values.
Florian Roth (Nextron Systems), Jason Lynch, Huntrule TeamWindowsprocess_creationHigh162Free2021-05-22Wazuh CVE-2021-26814 RCE Exploitation via Directory Traversal in Web Requests
Detects Wazuh-related web requests attempting path traversal through the /manager/files query parameter.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh235Free2021-05-22Windows: WinRM Service Process Spawning Command-Line and Scripting Utilities
Flags suspicious child shells and admin utilities spawned by the WinRM host process (wsmprovhost.exe) on Windows.
Andreas Hunkeler (@Karneades), Markus Neis, Huntrule TeamWindowsprocess_creationHigh293Free2021-05-20PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh2310Free2021-05-18AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
Alerts on CloudTrail ModifySnapshotAttribute events indicating EC2 snapshot permissions were changed for other-account access.
Darin Smith, Huntrule TeamAwscloudtrailMedium204Free2021-05-17Windows Process Command Lines Indicating ngrok.exe Tunnel Setup
Detects Windows executions of ngrok.exe with TCP/HTTP tunneling and authtoken/start-all YAML configuration patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh211Free2021-05-14Windows process creation patterns associated with DarkSide ransomware helpers
Detects Windows process creation consistent with DarkSide ransomware helper execution using encoded command-line content.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2021-05-14Webserver Indicators of Successful Exchange CVE-2021-28480 Exploitation via OWA Calendar POST
Flags POST requests to OWA calendar endpoint patterns linked to CVE-2021-28480, excluding HTTP 503 responses.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical162Free2021-05-14Windows: Detect Rclone command execution with exfiltration-oriented flags
Identifies likely rclone.exe exfiltration activity on Windows by matching command-line flags and rclone executable characteristics.
Bhabesh Raj, Sittikorn S, Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsprocess_creationHigh133Free2021-05-10