Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,456 rules
Web exploitation attempts for CVE-2023-43261 causing info disclosure in Milesight routers
Alerts on successful GET requests for /lang/log/httpd.log in Milesight router web access logs, consistent with CVE-2023-43261 disclosure attempts.
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule Team—webserverHigh447Free2023-10-20Potential Information Disclosure via CVE-2023-43261 in Milesight Router Proxy Logs
Alerts on HTTP GET 200 responses for UR router log paths in proxy requests associated with CVE-2023-43261.
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule Team—proxyHigh153Free2023-10-20Cisco IOS XE Web UI Exploitation Indicators for CVE-2023-20198 via Syslog Login and Config Events
Matches Cisco IOS XE Web UI and web login success logs consistent with CVE-2023-20198 exploitation using specified admin/TAC usernames.
Lars B. P. Frydenskov (Trifork Security), Huntrule TeamCiscosyslogHigh2010Free2023-10-20Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsfile_eventHigh368Free2023-10-19Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWindowsregistry_setLow132Free2023-10-18Windows Process Execution: curl.exe Downloading Files From an IP URL
Flags curl.exe commands that download via an IP-based URL using output/remote-name flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium383Free2023-10-18Windows CertOC.exe Downloads File From IP-Based URL Using -GetCACAPS
Flags CertOC.exe executions using an IP-based URL in the command line with -GetCACAPS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2023-10-18Windows DLL Sideloading via ImageLoad of mscoRee/colorui/mapistub/HID payload DLLs
Alerts on Windows processes loading DLLs from targeted ProgramShared/ProgramData paths consistent with DLL sideloading.
Thurein Oo, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh161Free2023-10-18Windows rundll32.exe calling DllRegisterServer from a non-standard DLL path
Detects rundll32.exe calling DllRegisterServer from command lines associated with non-standard DLL locations.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationMedium70Free2023-10-17Windows regsvr32.exe Silent DLL execution invoking DllRegisterServer from uncommon paths
Alerts on regsvr32.exe /s /e executions of DLLs from potentially suspicious locations that may trigger DllRegisterServer.
Andreas Braathen (mnemonic.io), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-10-17DarkGate-related Autoit3.exe execution with suspicious parent process (Windows)
Alerts on AutoIt3.exe execution when spawned from cmd.exe, KeyScramblerLogon.exe, or msiexec.exe, excluding common legitimate install paths.
Micah Babinski, Huntrule TeamWindowsprocess_creationHigh163Free2023-10-15Windows Autoit3.exe Created by Uncommon Process (curl.exe/KeyScramblerLogon.exe/etc.)
Alerts on Windows events where Autoit3.exe is created, with the producing process matching curl.exe or other uncommon executables.
Micah Babinski, Huntrule TeamWindowsfile_eventMedium112Free2023-10-15Windows Process Creation: CoercedPotato.exe Execution via ExploitId Parameters
Flags Windows process creation for CoercedPotato.exe with --exploitId and known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh253Free2023-10-11Windows Named Pipe Creation with "\coerced\" PipeName Segment
Detects Windows named pipe creations where the pipe name contains the '\coerced\' pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdHigh132Free2023-10-11Windows MSSQL Failed Logon (EventID 18456) From External Client IP
Alerts on MSSQL failed login attempts (Event 18456) from client IPs outside typical local/private ranges.
j4son, Huntrule TeamWindowsapplicationMedium133Free2023-10-11