Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Detect SolarWinds SUPERNOVA Webshell URL Access on Webservers (logoimagehandler.ashx)
Identifies webserver traffic consistent with SUPERNOVA webshell access targeting logoimagehandler.ashx with a clazz query parameter.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical334Free2020-12-17Windows: Suspicious Child Processes Spawned by sqlservr.exe
Alerts when SQL Server (sqlservr.exe) spawns suspicious command/system tools on Windows.
FPT.EagleEye Team, wagga, Huntrule TeamWindowsprocess_creationHigh157Free2020-12-11Fortinet SSL VPN Exploitation Attempt via Path Traversal in Web Requests (CVE-2018-13379)
Alerts on HTTP requests matching a Fortinet SSL VPN traversal-style query indicative of CVE-2018-13379 exploitation.
Bhabesh Raj, Huntrule Team—webserverCritical141Free2020-12-08Windows Process Tree: rundll32.exe launching wermgr.exe via DllRegisterServer
Flags rundll32.exe spawning wermgr.exe where rundll32 command line includes DllRegisterServer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2020-11-26Web server request pattern consistent with Oracle WebLogic CVE-2020-14882 exploitation
Detects WebLogic console exploitation attempts by matching encoded traversal patterns in HTTP URI query strings.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh339Free2020-11-02Windows Registry Run Key Modification via winekey or team9 backdoor
Detects registry Run key changes to "Backup Mgr" that may indicate persistence via winekey/team9.
omkar72, Huntrule TeamWindowsregistry_eventHigh151Free2020-10-30Windows PsExec Execution Triggered by psexec.exe Process Creation
Flags process creation of PsExec (psexec.exe / psexec.c), a tool often used for remote execution and potential lateral movement.
omkar72, Huntrule TeamWindowsprocess_creationMedium185Free2020-10-30Windows Credential Access via Reg Add in LSA Registry Paths
Alerts when reg add commands target LSA registry settings and scecli entries commonly abused for credential access.
Sreeman, Huntrule TeamWindowsprocess_creationMedium93Free2020-10-29Windows Process Creation: bitsadmin.exe BITS jobs with SetNotifyCmdLine or remote file additions
Alerts on bitsadmin.exe command lines using /SetNotifyCmdLine or /Addfile to execute after download or stage remote files.
Sreeman, Huntrule TeamWindowsprocess_creationMedium162Free2020-10-29Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh323Free2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventHigh152Free2020-10-29Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
Semanur Guneysu @semanurtg, oscd.community, Huntrule TeamWindowsprocess_creationHigh101Free2020-10-28Windows Registry Persistence via Office Test Startup Key
Flags registry changes to a Windows Office test startup key that may enable auto-execution of an arbitrary DLL.
omkar72, Huntrule TeamWindowsregistry_eventMedium456Free2020-10-25Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.
Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh262Free2020-10-23macOS Emond Launch Daemon Rule Install Monitoring via plist and emondClients Paths
Alerts on macOS Emond rule plist or emond client database changes that may indicate persistence setup.
Alejandro Ortuno, oscd.community, Huntrule TeamMacosfile_eventMedium141Free2020-10-23