Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Microsoft Exchange exploitation attempt via suspicious POST requests in web server logs
Flags POST traffic to Exchange OWA/ECP-related URLs with specific client and user-agent indicators consistent with exploitation attempts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh314Free2021-03-03Windows Exchange UMWorkerProcess File Drops Indicating CVE-2021-26858 Exploitation
Alerts on Exchange Unified Messaging (UMWorkerProcess.exe) creating unusual files, excluding common benign names consistent with CVE-2021-26858 activity.
Bhabesh Raj, Huntrule TeamWindowsfile_eventHigh433Free2021-03-03Windows Process Creation: Suspected CVE-2021-26857 Exploitation via UMWorkerProcess.exe
Detects suspicious child process spawning by Exchange Unified Messaging (UMWorkerProcess.exe) associated with CVE-2021-26857 attempts.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh288Free2021-03-03Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical123Free2021-02-26Windows Process Creation: finger.exe Execution
Alerts on Windows executions of finger.exe, a legacy utility that may indicate suspicious reconnaissance or network activity.
Florian Roth (Nextron Systems), omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh93Free2021-02-24Webserver POST to vROps uploadova endpoint indicative of CVE-2021-21972 exploitation
Alerts on POST requests to the uploadova endpoint tied to CVE-2021-21972 vSphere exploitation.
Bhabesh Raj, Huntrule Team—webserverHigh141Free2021-02-24Webserver URI Detects DEWMODE Webshell Access Attempts
Identifies webserver requests with DEWMODE webshell-specific URI query parameter patterns.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh122Free2021-02-22Windows ScreenConnect Installation Execution via Remote Access Parameters
Flags Windows executions of ScreenConnect with remote access command-line parameters indicating remote session setup.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2021-02-11Windows Process Creation: logman.exe Used to Stop or Delete ETW Trace Sessions
Alerts when logman.exe is used to stop or delete Windows ETW trace sessions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2110Free2021-02-11Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Detects AdFind executions on Windows that include common AD reconnaissance parameters.
Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh50Free2021-02-02Windows Audit Policy Tampering Using auditpol.exe Command-Line Flags
Flags auditpol.exe executions that disable, clear, remove, or restore Windows audit policy settings.
Janantha Marasinghe (https://github.com/blueteam0ps), Huntrule TeamWindowsprocess_creationHigh299Free2021-02-02Windows Process Creation: Detect ShimCache Flush via rundll32 apphelp.dll/kernel32.dll
Flags rundll32 command-line activity that flushes ShimCache via apphelp.dll or kernel32.dll entry points.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2021-02-01Windows rundll32.exe execution with no parameters or arguments
Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowsprocess_creationHigh111Free2021-01-31Windows WMIC Uninstall/Terminate Actions Targeting Security Products
Flags WMIC commands on Windows that attempt to uninstall or terminate security products or sensors using known vendor/product strings.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-01-30Windows Command-Line Disables Volume Shadow Copy (VSS) Snapshots
Flags Windows command lines that disable Volume Shadow Copy (VSS) snapshots via VSS Diag service switches.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2021-01-28