Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,524 rules
macOS Process Creation: MeshAgent Remote Access via --meshServiceName
Alerts on macOS process executions containing --meshServiceName, indicating potential MeshAgent remote access usage.
Norbert Jaśniewicz (AlphaSOC), Huntrule TeamMacosprocess_creationMedium150Free2025-05-19Webserver POST Uploads Java Web Shell Files in SAP NetViewer
Alerts on POST requests to /irj/ endpoints uploading Java extension files with octet-stream content type.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverHigh173Free2025-05-14SAP NetViewer Webshell Command Execution via JSP cmd Parameter
Alerts on SAP NetViewer JSP requests likely used as webshells to execute system commands via cmd-style query parameters.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule Team—webserverHigh317Free2025-05-14Windows WER BugCheck Crash Dump Reporting via Event ID 1001
Flags Windows WER SystemErrorReporting Event ID 1001 entries indicating a crash with bugcheck and dump/report details.
Jason Mull, Huntrule TeamWindowssystemMedium132Free2025-05-12Windows: Suspicious Command-Line Child Processes Spawned by SAP NetWeaver Paths
Flags SAP NetWeaver web work/root processes spawning Windows command/script tools that may indicate server-side execution.
Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2025-04-28Linux: Suspicious child processes spawned by SAP NetWeaver (web application directories)
Alerts when SAP NetWeaver work/root paths spawn common shells or utilities on Linux, indicating potential malicious command execution.
Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium3110Free2025-04-28Windows File Events: SAP NetWeaver Directory Webshell File Creation (.jsp/.java/.class)
Flags Windows file creation of JSP/Java/Class under SAP NetWeaver servlet_jsp work/root paths that may indicate webshell persistence.
Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventMedium163Free2025-04-28Linux File Events: Webshell-like JSP/Java/Class Creation in SAP NetWeaver Directories
Alerts on Linux file creation of .jsp/.java/.class under SAP NetWeaver IRJ servlet paths that may indicate webshell deployment.
Elastic (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxfile_eventMedium393Free2025-04-28Suspicious Inline JavaScript Execution by Node.js (node.exe) on Windows
Flags Windows command lines where node.exe is used with JavaScript execution indicators and module keywords consistent with malicious activity.
Microsoft (idea), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium464Free2025-04-21Windows Process Execution of JavaScript via Node.exe
Alerts when node.exe starts a process with a .js argument on Windows, which may indicate suspicious script execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationLow205Free2025-04-21Windows Suspicious .library-ms File Creation by 7z.exe, winrar.exe, or explorer.exe
Alerts on .library-ms file creation triggered by 7z.exe, winrar.exe, or explorer.exe, which may indicate forced-authentication style exploitation.
Gene Kazimiarovich, Huntrule TeamWindowsfile_eventMedium162Free2025-04-20Suspicious cmd.exe execution from w3wp.exe tied to CentreStack portal.config (Windows process creation)
Alerts when w3wp.exe launches cmd.exe and its command line references \portal\portal.config, suggesting possible IIS app exploitation.
Jason Rathbun (Blackpoint Cyber), Huntrule TeamWindowsprocess_creationHigh3810Free2025-04-17Windows: Suspicious child processes spawned by CrushFTP service
Alerts when CrushFTP service (crushftpservice.exe) launches shell/script executables like PowerShell, cmd, mshta, or bash.
Craig Sweeney, Matt Anderson, Jose Oregon, Tim Kasper, Faith Stratton, Samantha Shaw, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2025-04-10Windows Registry: MiniNt Key Added to Disable Security Event Logging on Reboot
Flags registry set activity that adds the MiniNt key, which stops Windows Event Log from writing events after a reboot.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh121Free2025-04-09Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2025-04-09