Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Windows Process Creation: Suspected CVE-2021-26857 Exploitation via UMWorkerProcess.exe
Detects suspicious child process spawning by Exchange Unified Messaging (UMWorkerProcess.exe) associated with CVE-2021-26857 attempts.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh308Free2021-03-03Windows Process Creation: finger.exe Execution
Alerts on Windows executions of finger.exe, a legacy utility that may indicate suspicious reconnaissance or network activity.
Florian Roth (Nextron Systems), omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh133Free2021-02-24Webserver POST to vROps uploadova endpoint indicative of CVE-2021-21972 exploitation
Alerts on POST requests to the uploadova endpoint tied to CVE-2021-21972 vSphere exploitation.
Bhabesh Raj, Huntrule Team—webserverHigh171Free2021-02-24Webserver URI Detects DEWMODE Webshell Access Attempts
Identifies webserver requests with DEWMODE webshell-specific URI query parameter patterns.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh142Free2021-02-22Windows Process Creation: logman.exe Used to Stop or Delete ETW Trace Sessions
Alerts when logman.exe is used to stop or delete Windows ETW trace sessions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2210Free2021-02-11Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Detects AdFind executions on Windows that include common AD reconnaissance parameters.
Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2021-02-02Windows Audit Policy Tampering Using auditpol.exe Command-Line Flags
Flags auditpol.exe executions that disable, clear, remove, or restore Windows audit policy settings.
Janantha Marasinghe (https://github.com/blueteam0ps), Huntrule TeamWindowsprocess_creationHigh319Free2021-02-02Windows Process Creation: Detect ShimCache Flush via rundll32 apphelp.dll/kernel32.dll
Flags rundll32 command-line activity that flushes ShimCache via apphelp.dll or kernel32.dll entry points.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2021-02-01Windows rundll32.exe execution with no parameters or arguments
Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowsprocess_creationHigh141Free2021-01-31Windows WMIC Uninstall/Terminate Actions Targeting Security Products
Flags WMIC commands on Windows that attempt to uninstall or terminate security products or sensors using known vendor/product strings.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-01-30Windows Command-Line Disables Volume Shadow Copy (VSS) Snapshots
Flags Windows command lines that disable Volume Shadow Copy (VSS) snapshots via VSS Diag service switches.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh211Free2021-01-28Webserver Detection: SonicWall SSL VPN Jarrewrite Exploitation URI and User-Agent Payloads
Flags web requests to /cgi-bin/jarrewrite.sh with user-agent indicators consistent with command injection exploitation.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh447Free2021-01-25Webserver detection of TerraMaster TOS CVE-2020-28188 exploit requests
Flags GET requests to /include/makecvs.php with Event plus indicators of script download/execute behavior tied to CVE-2020-28188.
Bhabesh Raj, Huntrule Team—webserverHigh185Free2021-01-25Windows Process Creation: 7z Archive Creation with Script/Command Launch Chaining
Flags Windows process creation chaining 7z archive commands with .zip plus .txt/.log extensions and wscript+rundll32 context.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2021-01-22Windows Process Creation: Raccine Removal via taskkill, registry and scheduled task deletion
Detects command-line activity that stops and removes Raccine components through process killing, registry deletion, and scheduled task removal.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2021-01-21