Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,511 rules
Suspicious Palo Alto GlobalProtect Session Unmarshal Path Traversal and Command Injection Attempts
Detects GlobalProtect logs with directory traversal/command injection-style indicators tied to CVE-2024-3400 behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamPaloaltoapplianceHigh151Free2024-04-18Cisco Duo MFA Success Triggered by Admin-Assigned Bypass Code
Alert on Duo successful MFA logins that are attributed to bypass-user codes.
Nikita Khalimonenkov, Huntrule TeamCiscoduoMedium246Free2024-04-17Linux Pnscan Binary Data Transfer via Command-Line
Flags Linux executions with Pnscan-like arguments indicating binary send/receive data transfer.
David Burkett (@signalblur), Huntrule TeamLinuxprocess_creationMedium112Free2024-04-16Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh529Free2024-04-15Kubernetes API Audit: Unauthorized (401) or Forbidden (403) Access Attempts
Alerts on Kubernetes API audit events returning 401 or 403, indicating authentication or authorization failures.
kelnage, Huntrule TeamKubernetesauditLow532Free2024-04-12Linux sshd Spawns Root Shell Script Commands Suggesting CVE-2024-3094 Exploitation
Alerts on sshd spawning bash/sh one-liners as root, a potential indicator of CVE-2024-3094 style exploitation.
Arnim Rupp, Nasreddine Bencherchali, Thomas Patzke, Huntrule TeamLinuxprocess_creationHigh213Free2024-04-01Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication
Alerts on Azure AD changes that add a new trusted root CA for passwordless certificate-based authentication.
Harjot Shah Singh, '@cyb3rjy0t', Huntrule TeamAzureauditlogsMedium161Free2024-03-26Azure AD Audit Logs: Certificate-based authentication enabled via AuthenticationMethodsPolicy update
Flags Azure AD audit log events where the Authentication Methods policy is updated to enable certificate-based authentication.
Harjot Shah Singh, '@cyb3rjy0t', Huntrule TeamAzureauditlogsMedium256Free2024-03-26Kubernetes Audit: Sidecar Injection via kubectl patch to Deployments
Detects PATCH operations against Kubernetes Deployments that may indicate sidecar-style container injection.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationMedium282Free2024-03-26Kubernetes Service Account Created via Audit Log
Alerts on Kubernetes audit events showing new ServiceAccounts created.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow461Free2024-03-26Kubernetes Audit: Listing Secrets (Enumeration of Secret Resources)
Alerts on Kubernetes audit requests that list the secrets resource, consistent with secret enumeration.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow133Free2024-03-26Kubernetes RBAC SelfSubjectRulesReview Permission Enumeration Attempt
Alerts on Kubernetes selfsubjectrulesreviews API calls that enumerate the caller’s RBAC permissions.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow122Free2024-03-26Kubernetes Privileged Pod Created via Pod Creation Requests
Flags Kubernetes pod creates where container capabilities are set to all, indicating possible privileged access setup.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow384Free2024-03-26Kubernetes Audit: Pod Creation in kube-system Namespace
Flags Kubernetes audit events creating pods in the kube-system namespace, a common place to camouflage malicious workloads.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationMedium453Free2024-03-26Kubernetes Pod Created With hostPath Volume Mount
Alerts on Kubernetes pod creation requests that include a hostPath volume mount.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow226Free2024-03-26