Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,289 rules
Windows Fax Service ualapi.dll Side-Loading via fxssvc.exe
Flags fxssvc.exe loading ualapi.dll from unexpected paths, indicating potential DLL side-loading for privilege escalation.
NVISO, Huntrule TeamWindowsimage_loadHigh72Free2020-05-04Windows Process Creation: .NET ETW Logging Environment Variables Set via Command Line
Flags process command lines setting COMPlus_ETWEnabled/COMPlus_ETWFlags, potentially impairing ETW logging for .NET.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_creationHigh346Free2020-05-02Windows: Alert on Suspicious HH.EXE Process Execution
Alerts on HH.exe execution where the command line references temp, downloads, Outlook, or other writable directories.
Maxim Pavlunin, Huntrule TeamWindowsprocess_creationHigh71Free2020-04-01Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2020-04-01Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
NVISO, Huntrule TeamWindowsps_scriptHigh132Free2020-03-26Windows Process Creation: Java exploitation chain targeting Zoho ManageEngine Desktop Central (CVE-2020-10189)
Alerts on cmd/Pwsh/BITSAdmin and other command utilities launched by the Desktop Central Java runtime.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2020-03-25Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
Teymur Kheirkhabarov, Harish Segar, Huntrule TeamWindowsprocess_creationHigh268Free2020-03-20Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Alerts on Zeek SMB file events suggesting Impacket SecretDump-style staging in ADMIN$ under SYSTEM32 with .tmp files.
Samir Bousseaden, @neu5ron, Huntrule TeamZeeksmb_filesHigh293Free2020-03-19Webserver Detection of POST Logupload Attempt for VMware View Planner CVE-2021-21978
Alerts on webserver POST requests targeting logupload/logMetaData parameters tied to CVE-2021-21978 probing.
Bhabesh Raj, Huntrule Team—webserverHigh408Free2020-03-10Windows: Suspicious Execution of CSharp Interactive Console via PowerShell
Alerts when PowerShell launches csi.exe, indicating possible interactive .NET code execution.
Michael R. (@nahamike01), Huntrule TeamWindowsprocess_creationHigh142Free2020-03-08Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe
Alerts when svchost.exe launches mmc.exe with “-Embedding”, indicating potential MMC20 COM-based lateral movement.
"@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea), Huntrule Team"Windowsprocess_creationHigh437Free2020-03-04Windows: Detect Microsoft Exchange CVE-2020-0688 exploitation via Eventlog errors
Identifies Exchange Control Panel error events containing a ViewState parameter consistent with CVE-2020-0688 exploitation attempts.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowsapplicationHigh441Free2020-02-29Webserver Request Matching for CVE-2020-0688 Exploitation Attempt
Alerts when webserver URI queries include /ecp/default.aspx with __VIEWSTATEGENERATOR and __VIEWSTATE consistent with CVE-2020-0688 probing.
NVISO, Huntrule Team—webserverHigh206Free2020-02-27Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
Flags HTTP GET URIs containing SQL injection indicator strings in webserver access logs, excluding 404 responses.
Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank), Huntrule TeamWebwebserverHigh162Free2020-02-22Windows: Office Application Loads VBE VBA DLLs via Image Load Events
Flags Office apps loading VBA-related VBE DLLs, a strong indicator of VBA macro execution.
Antonlovesdnb, Huntrule TeamWindowsimage_loadHigh132Free2020-02-19