Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,295 rules
Windows: SQLCmd used to dump database metadata and backups
Alerts on Windows executions of sqlcmd.exe with local server targeting and database enumeration/backup query fragments.
frack113, Huntrule TeamWindowsprocess_creationHigh453Free2021-08-16Webserver GET requests containing XSS-related payload strings
Finds likely XSS injection attempts in webserver GET requests by matching script, tag, and JS payload strings while excluding 404s.
Saw Win Naung, Nasreddine Bencherchali, Huntrule TeamWebwebserverHigh358Free2021-08-15Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Flags winword.exe process injection where the call trace matches LittleCorporal-generated Maldoc activity on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh132Free2021-08-09PowerShell ShellIntel Commandlet Abuse via ScriptBlock Logging
Flags PowerShell script blocks that reference known ShellIntel commandlets tied to exploitation activity.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsps_scriptHigh121Free2021-08-09AWS CloudTrail UpdateLoginProfile: Password/Authentication Profile Modified for Another User
Flags AWS IAM UpdateLoginProfile events where an account updates another user’s login profile password.
toffeebr33k, Huntrule TeamAwscloudtrailHigh3510Free2021-08-09Windows Process Creation: Detects Volume Shadow Copy Listing via vssadmin
Alerts on Windows command lines that list VSS shadow copies and write results to log.txt.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2021-08-09Detects ProxyShell-Style Exchange Probing via /autodiscover.json and PowerShell URIs (HTTP 401)
Flags Exchange web requests with ProxyShell-like /autodiscover.json query patterns and PowerShell/EWS-related parameters, often returning HTTP 401.
Florian Roth (Nextron Systems), Rich Warren, Huntrule Team—webserverHigh248Free2021-08-07Windows AnyDesk Silent Installation via Command-Line Flags
Identifies AnyDesk being silently installed on Windows using --install, --start-with-win, and --silent command-line flags.
Ján Trenčanský, Huntrule TeamWindowsprocess_creationHigh193Free2021-08-06Windows Registry: Disabling Windows Defender PUA Protection via PUAProtection DWORD
Flags registry changes that set Windows Defender PUAProtection DWORD to 0x00000000 to disable PUA protection.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setHigh226Free2021-08-04Windows process access matching Cobalt Strike BOF injection call trace
Flags suspicious Windows process access consistent with CobaltStrike BOF injection using ntdll/KERNELBASE call traces and high GrantedAccess.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh183Free2021-08-04Windows Process Creation: ADCSPwn Command-Line Parameters Indicating ADCS Abuse
Identifies Windows processes with command-line arguments consistent with ADCSPwn targeting ADCS and a specified port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh459Free2021-07-31Windows Named Pipe Creation: Cobalt Strike Malleable Profile PipeName Patterns
Alerts on Sysmon named pipe creation with PipeName patterns commonly used by Cobalt Strike malleable C2.
Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule TeamWindowspipe_createdHigh151Free2021-07-30Windows WinDivert Driver Load via Image or Known IMPHASHes
Detects WinDivert-related Windows driver loads using loaded image paths or known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh173Free2021-07-30PowerShell SAM Hive Copy via Volume Shadow Copy Paths on Windows
Flags PowerShell commands that copy the SAM hive from Volume Shadow Copy locations using .NET or PowerShell copy semantics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh339Free2021-07-29Windows Process Creation: Impacket HackTool Binary Execution via Named Image Matches
Flags execution of Windows impacket compiled binaries based on distinctive tool names in the process Image.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh469Free2021-07-24