Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,279 rules
Windows Scheduled Task Creation via PowerShell Using schtasks.exe with ONLOGON/DAILY/ONIDLE/HOURLY
Flags PowerShell-launched schtasks.exe /Create commands matching default PowerSploit/Empire scheduled task persistence behavior.
Markus Neis, @Karneades, Huntrule TeamWindowsprocess_creationHigh261Free2018-03-06Windows rundll32 Trojan Loader Execution via Local AppData and .dat Parameters
Flags rundll32.exe launched with AppData/local .dat and .dll patterns consistent with Trojan loader behavior.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh112Free2018-03-01Linux syslog: Detect suspicious BIND/named error messages
Alerts on Linux syslog messages with BIND named fatal or denied DNS error strings.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsyslogHigh92Free2018-02-20Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.
Roberto Rodriguez (source), Dominik Schaudel (rule), Huntrule TeamWindowssecurityHigh80Free2018-02-12Windows System Binary Execution From Unusual Location (Process Creation)
Alerts when common Windows system binaries run from an uncommon directory rather than standard system locations.
Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh412Free2017-11-27Web/SQL Application Logs: SQL Error Strings Indicative of Injection Probing
Flags SQL error log messages with injection-probing syntax/quoting/UNION mismatch keywords.
Bjoern Kimminich, Huntrule TeamSqlapplicationHigh161Free2017-11-27Windows File Events: java.exe in AppData\Roaming\Oracle\bin Path with .exe and .vbs Artifacts
Alerts on Windows file events for suspicious java*.exe placement in AppData\Roaming\Oracle\bin and .vbs files containing "Retrive".
Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsfile_eventHigh435Free2017-11-10Windows Process Creation: javaw.exe Command Line Indicates Adwind/JRAT Roaming Oracle Path
Flags command-line patterns indicating javaw.exe execution from AppData\Roaming\Oracle with java/.exe markers.
Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2017-11-10Proxy Web Requests for Flash Player Installer from Unofficial Locations
Flags proxy downloads for Flash Player installer paths when the request host is not ending in .adobe.com.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh113Free2017-10-25Windows: Detect Renamed ps.exe Executing netstat via cmd /c
Alerts on Windows executions of renamed PsTool-like ps.exe that include accept-eula and netstat via cmd.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh286Free2017-10-22Linux JexBoss Suspicious Bash Command Launch with /dev/tcp
Flags Linux executions containing bash -c /bin/bash paired with /dev/tcp/ indicative of a reverse-shell command sequence.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High458Free2017-08-24Linux Suspicious Shell Command Lines for Exploit/Payload Delivery
Detects Linux command-line strings matching wget/piping, payload staging, permission changes, and socat/HTTP server execution patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High4210Free2017-08-21Windows Security: Account Encryption/Preauth/Delegation Flags Weakened in User Account Changes
Flags Windows Event ID 4738 user account changes that enable weaker encryption or related pre-auth behavior.
"@neu5ron, Huntrule Team"WindowssecurityHigh445Free2017-07-30Windows Security: SeEnableDelegationPrivilege Enabled via AD User Right (Event 4704)
Alerts when Event ID 4704 assigns SeEnableDelegationPrivilege, enabling control over other AD user objects.
"@neu5ron, Huntrule Team"WindowssecurityHigh401Free2017-07-30Suspicious Malformed User-Agent Strings in Proxy Logs
Flags proxy requests whose User-Agent headers are malformed or match suspicious automation/tooling patterns, excluding known Adobe/Acrobat traffic.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh125Free2017-07-08