Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
Teymur Kheirkhabarov, Harish Segar, Huntrule TeamWindowsprocess_creationHigh268Free2020-03-20PowerShell Downgrade Attempts via -Version 2 on Windows Process Creation
Alerts on PowerShell executions specifying a -Version 2 argument, consistent with potential downgrade attempts.
Harish Segar (rule), Huntrule TeamWindowsprocess_creationMedium281Free2020-03-20Windows Desktop.ini Accessed by Uncommon Process
Alerts when unexpected processes create or access Desktop.ini, which can be abused to change how Explorer displays folder contents.
Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO), Huntrule TeamWindowsfile_eventMedium92Free2020-03-19Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Alerts on Zeek SMB file events suggesting Impacket SecretDump-style staging in ADMIN$ under SYSTEM32 with .tmp files.
Samir Bousseaden, @neu5ron, Huntrule TeamZeeksmb_filesHigh293Free2020-03-19Zeek DCE-RPC spoolss and IRemoteWinspool Calls Indicating Windows Print-Related Persistence
Alerts on specific Zeek DCE-RPC endpoint/operation combinations linked to Windows persistence techniques.
"@neu5ron, SOC Prime, Huntrule Team"Zeekdce_rpcMedium3110Free2020-03-19Zeek DCE-RPC Execution Indicators: JobAdd, Task Scheduler RPC, WMI ExecMethod, and Service Creation/Start
Detects Zeek DCE-RPC calls that match execution-related JobAdd, Task Scheduler, WMI, or service create/start operations.
"@neu5ron, SOC Prime, Huntrule Team"Zeekdce_rpcMedium123Free2020-03-19Windows Process Execution of .SettingContent-ms Command Line
Flags Windows processes whose command lines reference .SettingContent-ms, a potential trigger for setting-based execution.
Sreeman, Huntrule TeamWindowsprocess_creationMedium317Free2020-03-13Windows: Alert on Uncommon Child Process Executed from Appvlp.exe
Alerts on unusual child processes created by Appvlp.EXE on Windows, indicating potential command execution abuse.
Sreeman, Huntrule TeamWindowsprocess_creationMedium63Free2020-03-13Webserver Detection of POST Logupload Attempt for VMware View Planner CVE-2021-21978
Alerts on webserver POST requests targeting logupload/logMetaData parameters tied to CVE-2021-21978 probing.
Bhabesh Raj, Huntrule Team—webserverHigh408Free2020-03-10Windows: Suspicious Execution of CSharp Interactive Console via PowerShell
Alerts when PowerShell launches csi.exe, indicating possible interactive .NET code execution.
Michael R. (@nahamike01), Huntrule TeamWindowsprocess_creationHigh142Free2020-03-08Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe
Alerts when svchost.exe launches mmc.exe with “-Embedding”, indicating potential MMC20 COM-based lateral movement.
"@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea), Huntrule Team"Windowsprocess_creationHigh427Free2020-03-04Windows: Detect Microsoft Exchange CVE-2020-0688 exploitation via Eventlog errors
Identifies Exchange Control Panel error events containing a ViewState parameter consistent with CVE-2020-0688 exploitation attempts.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowsapplicationHigh441Free2020-02-29Microsoft Exchange Web RCE Attempts via GET Requests Containing ECP/OWA and __VIEWSTATE
Alerts on web requests to Exchange ECP/OWA that include __VIEWSTATE= in the query.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical312Free2020-02-29Webserver Request Matching for CVE-2020-0688 Exploitation Attempt
Alerts when webserver URI queries include /ecp/default.aspx with __VIEWSTATEGENERATOR and __VIEWSTATE consistent with CVE-2020-0688 probing.
NVISO, Huntrule Team—webserverHigh206Free2020-02-27Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
Flags HTTP GET URIs containing SQL injection indicator strings in webserver access logs, excluding 404 responses.
Saw Win Naung, Nasreddine Bencherchali (Nextron Systems), Thurein Oo (Yoma Bank), Huntrule TeamWebwebserverHigh162Free2020-02-22