Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Windows Service Installation (EID 4697) for SMB PsExec by Metasploit or Impacket
Alerts on Windows Event ID 4697 service installs matching SYSTEMROOT\8char.exe and on-demand start, consistent with PsExec-style SMB execution.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowssecurityHigh163Free2021-01-21Windows Plink Remote Port Forwarding via -R Command Line
Alerts on Windows process command lines using Plink " -R " remote port forwarding to a local port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh406Free2021-01-19Windows System Log: NTFS File System Driver Event 55 Indicates Possible NTFS Exploitation
Alerts on Windows NTFS Event ID 55 indicating a corrupted file record with a matching filename string in the event description.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh322Free2021-01-11Cisco ASA FTD web exploitation attempt matching CVE-2020-3452 with HTTP 200
Detects HTTP 200 requests targeting Cisco ASA/FTD web parameters associated with CVE-2020-3452 exploit behavior.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh404Free2021-01-07Windows: Suspicious Child Processes Spawned by sqlservr.exe
Alerts when SQL Server (sqlservr.exe) spawns suspicious command/system tools on Windows.
FPT.EagleEye Team, wagga, Huntrule TeamWindowsprocess_creationHigh187Free2020-12-11Windows Process Tree: rundll32.exe launching wermgr.exe via DllRegisterServer
Flags rundll32.exe spawning wermgr.exe where rundll32 command line includes DllRegisterServer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2020-11-26Web server request pattern consistent with Oracle WebLogic CVE-2020-14882 exploitation
Detects WebLogic console exploitation attempts by matching encoded traversal patterns in HTTP URI query strings.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh369Free2020-11-02Windows Registry Run Key Modification via winekey or team9 backdoor
Detects registry Run key changes to "Backup Mgr" that may indicate persistence via winekey/team9.
omkar72, Huntrule TeamWindowsregistry_eventHigh191Free2020-10-30Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh363Free2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventHigh162Free2020-10-29Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
Semanur Guneysu @semanurtg, oscd.community, Huntrule TeamWindowsprocess_creationHigh131Free2020-10-28Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.
Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh272Free2020-10-23Windows Registry: Detect esentutl.exe activity under VSS service keys
Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh192Free2020-10-20Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_accessHigh171Free2020-10-20macOS Process Creation: grep 'password' or laZagne Credential Extraction
Detects macOS executions of grep targeting 'password' strings and laZagne, suggesting local credential extraction attempts.
Igor Fits, Mikhail Larin, oscd.community, Huntrule TeamMacosprocess_creationHigh121Free2020-10-19