Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,297 rules
Windows Process Memory Dump Using RdrLeakDiag.exe (/memdmp|fullmemdmp)
Alerts on Windows executions of rdrleakdiag.exe that request full or targeted memory dumps via /memdmp or /fullmemdmp.
Cedric MAURUGEON, Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4610Free2021-09-24VMware vCenter Server file upload exploitation attempt for CVE-2021-22005 via POST telemetry endpoint
Identifies POST requests targeting a vCenter telemetry upload endpoint consistent with CVE-2021-22005 exploitation attempts.
Sittikorn S, Huntrule Team—webserverHigh82Free2021-09-24PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsps_scriptHigh163Free2021-09-21Windows: Xwizard.exe Execution from Non-Default Directory
Alerts when Xwizard.exe starts from an unexpected Windows path, indicating potential misuse or side-loading.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh455Free2021-09-20Detect suspicious AD SelfService web requests targeting report generation and API endpoints
Flags web requests with URL query strings targeting known ADSelfService exploitation paths for CVE-2021-40539.
Tobias Michalski (Nextron Systems), Max Altgelt (Nextron Systems), Huntrule Team—webserverHigh60Free2021-09-20Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Alert on HTTP 200 POST /wsman with no Authorization header and a non-empty body in Zeek logs, consistent with OMIGOD unauthenticated RCE attempts.
Nate Guagenti (neu5ron), Huntrule TeamZeekhttpHigh296Free2021-09-20PowerShell Add-DnsClientNrptRule Modifies NRPT Namespaces
Flags PowerShell scripts that add DNS Name Resolution Policy Table rules for a specified namespace.
Borna Talebi, Huntrule TeamWindowsps_scriptHigh192Free2021-09-14Linux Commands Clearing or Removing /var/log/syslog
Flags Linux activity that clears, deletes, or redirects /var/log/syslog, a likely attempt to impair logging.
Max Altgelt (Nextron Systems), Huntrule TeamLinux—High123Free2021-09-10Windows Winword.exe Creates INetCache .cab and .inf Files During CVE-2021-40444 Exploitation
Flags winword.exe writing CABs in INetCache or INF files in Temp consistent with CVE-2021-40444 exploitation.
Florian Roth (Nextron Systems), Sittikorn S, Huntrule TeamWindowsfile_eventHigh161Free2021-09-10Windows Process Execution of control.exe Spawned by Office Apps Matching CVE-2021-40444 Pattern
Alerts when control.exe is launched from Office apps with suspicious DLL-related command lines, consistent with CVE-2021-40444 exploitation attempts.
Florian Roth (Nextron Systems), @neonprimetime, Huntrule TeamWindowsprocess_creationHigh122Free2021-09-08Windows Process Creation: Atlassian Confluence Java Spawns Suspicious Utility Child Processes (CVE-2021-26084)
Flags suspicious child processes spawned by Confluence’s Java on Windows, consistent with attempted CVE-2021-26084 exploitation.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh131Free2021-09-08Windows Image Load of clfsw32.dll by svchost.exe indicating PRIVATELOG usage
Alert on svchost.exe loading clfsw32.dll, a rarely observed Windows image load pattern consistent with PRIVATELOG.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2021-09-07Windows Kerberos TGT Request with AD CS Certificate Thumbprint Anomalies (EventID 4768)
Identifies unusual certificate-associated Kerberos TGT (4768) requests targeting computer accounts on Windows.
Mauricio Velazco, Michael Haag, Huntrule TeamWindowssecurityHigh82Free2021-09-02Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowswmi_eventHigh364Free2021-09-01Windows Atera RMM Agent Installation via MsiInstaller Event ID 1033
Flags Windows MSI installs where installer logs indicate an AteraAgent installation (EventID 1033, MsiInstaller).
Bhabesh Raj, Huntrule TeamWindowsapplicationHigh112Free2021-09-01