Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Webserver Detection: SonicWall SSL VPN Jarrewrite Exploitation URI and User-Agent Payloads
Flags web requests to /cgi-bin/jarrewrite.sh with user-agent indicators consistent with command injection exploitation.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh417Free2021-01-25Webserver detection of TerraMaster TOS CVE-2020-28188 exploit requests
Flags GET requests to /include/makecvs.php with Event plus indicators of script download/execute behavior tied to CVE-2020-28188.
Bhabesh Raj, Huntrule Team—webserverHigh165Free2021-01-25Windows Security: Detect Scheduled Task Deletion (EventID 4699)
Flags Windows scheduled task deletions from Security EventID 4699 while excluding common MRT and Firefox-related tasks.
David Strassegger, Tim Shelton, Huntrule TeamWindowssecurityLow70Free2021-01-22Windows Process Creation: 7z Archive Creation with Script/Command Launch Chaining
Flags Windows process creation chaining 7z archive commands with .zip plus .txt/.log extensions and wscript+rundll32 context.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2021-01-22Windows Process Creation: Raccine Removal via taskkill, registry and scheduled task deletion
Detects command-line activity that stops and removes Raccine components through process killing, registry deletion, and scheduled task removal.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2021-01-21Windows Service Installation (EID 4697) for SMB PsExec by Metasploit or Impacket
Alerts on Windows Event ID 4697 service installs matching SYSTEMROOT\8char.exe and on-demand start, consistent with PsExec-style SMB execution.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowssecurityHigh163Free2021-01-21Web server requests targeting WebLogic JNDI LDAP via JndiBindingHandle (CVE-2021-2109)
Alerts on GET requests with WebLogic JndiBindingHandle and an ldap:// payload targeting AdminServer.
Bhabesh Raj, Huntrule Team—webserverCritical409Free2021-01-20Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Flags Windows command lines where PowerShell/WMI is used to spawn rundll32 from c:\windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical143Free2021-01-20Windows Plink Remote Port Forwarding via -R Command Line
Alerts on Windows process command lines using Plink " -R " remote port forwarding to a local port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh406Free2021-01-19Windows System Log: NTFS File System Driver Event 55 Indicates Possible NTFS Exploitation
Alerts on Windows NTFS Event ID 55 indicating a corrupted file record with a matching filename string in the event description.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh312Free2021-01-11Windows Registry Persistence via VSTO Add-ins in Microsoft Office
Flags registry writes that register VSTO/Office add-ins for Outlook, Word, Excel, or PowerPoint persistence on Windows.
Bhabesh Raj, Huntrule TeamWindowsregistry_setMedium133Free2021-01-10Cisco ASA FTD web exploitation attempt matching CVE-2020-3452 with HTTP 200
Detects HTTP 200 requests targeting Cisco ASA/FTD web parameters associated with CVE-2020-3452 exploit behavior.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh404Free2021-01-07SolarWinds Orion Web API auth bypass probing via suspicious WebResource requests
Detects likely SolarWinds Orion API authentication bypass probing by matching suspicious WebResource/i18n endpoint query strings while filtering known valid requests.
Bhabesh Raj, Tim Shelton, Huntrule Team—webserverCritical182Free2020-12-27Windows rundll32.exe Command-Line RunDLL or Control_RunDLL Execution
Alerts on rundll32.exe process launches whose command lines end with RunDLL/Control_RunDLL, indicative of DLL function loading.
FPT.EagleEye, Huntrule TeamWindowsprocess_creationCritical201Free2020-12-25Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution
Alerts on Windows process executions with command-line substrings consistent with behaviors described in Lazarus activity reports.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowsprocess_creationCritical4110Free2020-12-23