Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows DNS Server CVE-2020-1350 RCE Indicators via Suspicious Child Process Creation
Alerts on non-benign subprocesses spawned by Windows DNS (dns.exe), consistent with CVE-2020-1350 exploitation attempts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical172Free2020-07-15Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
Bhabesh Raj, Huntrule TeamWindowswindefendHigh113Free2020-07-14Windows Sysmon Operational Channel Reference Deleted via Security Event
Detects Security log events showing Sysmon Operational channel being disabled via channel reference deletion-like changes.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh111Free2020-07-14Empire C2 Proxy Requests with Specific User-Agent and POSTed PHP URIs
Flags proxy HTTP POSTs using an Empire-like user agent to specific admin/login PHP endpoints.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh335Free2020-07-13Windows Dllhost.exe Network Connections to Non-Local IP Addresses
Flags Dllhost.exe initiating outbound connections to non-local destination IPs, excluding local/private and specified benign IP ranges.
bartblaze, Huntrule TeamWindowsnetwork_connectionMedium50Free2020-07-13Windows Process Creation: regsvr32 Invoked to Load .ocx from AppData Roaming
Flags regsvr32 /s /i loading an .ocx from AppData\Roaming on Windows, a stealthy code-loading technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical91Free2020-07-10Citrix ADC/ADS Exploitation Attempts Targeting RAPI and PCIDSS Paths (CVE-2020-8193/8195)
Flags Citrix ADC/NetScaler HTTP requests whose URI queries match exploitation-related patterns for CVE-2020-8193 and CVE-2020-8195.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical123Free2020-07-10Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2020-07-09Windows Registry Run Key Modification for ntkd Persistence
Flags Windows registry activity hitting the Run key path segment "\Run\ntkd" used for automatic startup persistence.
Aidan Bracher, Huntrule TeamWindowsregistry_eventCritical121Free2020-07-07Microsoft 365 Impossible Travel Sign-ins Reported as Successful
Alerts on successful Microsoft 365 “Impossible travel activity” events in SecurityComplianceCenter telemetry.
Austin Songer @austinsonger, Huntrule TeamM365threat_managementMedium224Free2020-07-06Web Exploitation Attempt Pattern for CVE-2020-5902 on F5 BIG-IP (URI Traversal)
Alerts on web requests with query patterns consistent with CVE-2020-5902 exploitation attempts targeting F5 BIG-IP.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical92Free2020-07-05Windows Process Execution of DIT Snapshot Viewer (ditsnap.exe)
Alerts on execution of the DIT snapshot viewer tool ditsnap.exe on Windows.
Furkan Caliskan (@caliskanfurkan_), Huntrule TeamWindowsprocess_creationHigh277Free2020-07-04Windows Process Execution: Copy From System Directories to Other Locations
Detects cmd.exe, PowerShell, and copy utilities copying files from System32/SysWOW64/WinSxS to other locations on disk.
Florian Roth (Nextron Systems), Markus Neis, Tim Shelton (HAWK.IO), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2020-07-03Windows desktopimgdownldr Suspicious URL and Registry Modification via Command Line
Flags desktopimgdownldr command lines indicating potential external file download or personalization registry deletion.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh458Free2020-07-03Windows curl.exe Suspicious Download to Local File Paths
Flags curl.exe executions on Windows that appear to download to local files in suspicious directories with risky file extensions.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2020-07-03