Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,458 rules
Windows Network Connections to Visual Studio Code Tunnels Domain
Alerts on initiated network connections to .tunnels.api.visualstudio.com from a Windows process.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium112Free2023-11-20Windows Network Connections to *.devtunnels.ms
Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium111Free2023-11-20Windows Process Creation: Detect Event Log Query via wmic.exe, wevtutil.exe, or PowerShell
Detects command-line attempts to query Windows Event Logs using wevtutil, wmic, or Get-WinEvent/Get-EventLog.
Ali Alwashali, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-11-20Webserver POST requests to Confluence setup/restore endpoints matching CVE-2023-22518 exploit traffic
Detects POST traffic to Confluence CVE-2023-22518 vulnerable endpoints based on URI patterns and HTTP status codes.
Andreas Braathen (mnemonic.io), Huntrule Team—webserverMedium142Free2023-11-14HTTP POST exploitation attempt against Confluence CVE-2023-22518 vulnerable setup endpoints (Proxy logs)
Flags proxy POST requests to known Confluence setup/admin endpoints returning 200/302/405, aligned with CVE-2023-22518 exploitation attempts.
Andreas Braathen (mnemonic.io), Huntrule Team—proxyMedium123Free2023-11-14Windows: Detects Suspicious cmd.exe or PowerShell spawned from Confluence (tomcat) Processes
Alerts when Confluence/embedded Tomcat spawns cmd.exe or PowerShell on Windows, indicating possible command execution after exploitation.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationMedium81Free2023-11-14CVE-2023-22518 Confluence Exploitation Attempt via Suspicious Bash/Curl/Wget Child Processes on Linux
Alerts when Confluence Java spawns shell/download tools on Linux consistent with CVE-2023-22518 exploitation behavior.
Andreas Braathen (mnemonic.io), Huntrule TeamLinuxprocess_creationHigh409Free2023-11-14Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
Alerts when excel.exe spawns foxprow.exe, schdplus.exe, or winproj.exe, consistent with suspicious Excel DCOM automation activity.
Aaron Stratton, Huntrule TeamWindowsprocess_creationHigh143Free2023-11-13Windows: Command-Line Use of ms-appinstaller Protocol Handler for File Downloads
Alerts on Windows command lines invoking ms-appinstaller with an http source, indicating potential remote file download behavior.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium252Free2023-11-09Windows msxsl.exe Execution with HTTP Keyword in Command Line
Flags execution of msxsl.exe when the command line includes an HTTP URL indicator.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh70Free2023-11-09Windows: File Download via msedge_proxy.exe Using HTTP/HTTPS URLs
Flags msedge_proxy.exe executions that include HTTP/HTTPS URLs, consistent with arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium168Free2023-11-09Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS
Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh383Free2023-11-09Windows: Detect SysAid user.exe Loader Execution by Filename and SHA256 Hash
Flags execution of a specific SysAid-hosted Windows binary when the process image path and SHA256 match.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2023-11-09Windows Process Execution for PowerShell Cobalt Strike Download via Hidden IEX
Flags PowerShell command lines that use IEX and hidden downloadstring to fetch a Cobalt Strike payload.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2023-11-09Windows PowerShell script launcher matching SysAidServer Tomcat paths
Flags PowerShell script block text tied to SysAid Tomcat webapp paths and user.exe staging/launch actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh123Free2023-11-09