Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Proxy logs: suspicious exploit framework User-Agent strings
High-severity match on proxy User-Agent strings commonly seen in exploit/pentest frameworks.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh142Free2017-07-08Proxy HTTP Requests with Empty User-Agent Header
Flags proxy HTTP traffic with an empty User-Agent header, which may indicate automation or unusual client behavior.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium41Free2017-07-08Linux VSFTPD Logs: Suspicious Error Messages Indicating Possible Exploitation Attempts
Looks for specific vsftpd error strings that may indicate exploitation-triggered faults or abnormal request handling.
Florian Roth (Nextron Systems), Huntrule TeamLinuxvsftpdMedium96Free2017-07-05Linux SSHD Logs: Suspicious OpenSSH Daemon Error Keywords
Alerts on sshd log entries with specific OpenSSH fatal or cryptographic error messages indicating suspicious access attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsshdMedium53Free2017-06-30Windows Security Events Indicating File Deletion Attempts Using SDelete Extensions
Alerts on Windows security file access events for object names ending in .AAA or .ZZZ, consistent with secure deletion behavior.
Thomas Patzke, Huntrule TeamWindowssecurityMedium81Free2017-06-14Windows WCE wceaux.dll File Access via Security Event 4656/4663
Identifies Windows Security event activity involving access to the wceaux.dll library file.
Thomas Patzke, Huntrule TeamWindowssecurityCritical92Free2017-06-14Windows PsExec Service Execution via PSEXESVC.exe
Detects PsExec service execution by matching the PSEXESVC.exe process on Windows.
Thomas Patzke, Romaissa Adjailia, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2017-06-12Windows: PsExec Service File Creation via PSEXESVC.exe Written to Disk
Flags Windows file creation of \PSEXESVC.exe, indicating potential PsExec service deployment for remote execution.
Thomas Patzke, Huntrule TeamWindowsfile_eventLow122Free2017-06-12Windows PsExec Service Installation via Service Control Manager (Event ID 7045)
Flags Service Control Manager Event ID 7045 when a PSEXESVC service is installed with ImagePath ending in \PSEXESVC.exe.
Thomas Patzke, Huntrule TeamWindowssystemMedium111Free2017-06-12Windows Named Pipe Creation for PsExec Default Pipe
Alerts on creation of the default PsExec named pipe (\\PSEXESVC) using Windows named pipe creation telemetry.
Thomas Patzke, Huntrule TeamWindowspipe_createdLow50Free2017-06-12Windows Process Creation: Suspicious Execution of PlugX DLL Side-Loading Utilities from Uncommon Paths
Alerts on execution of PlugX-related helper binaries from atypical paths, excluding common legitimate directories.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2017-06-12Windows Process Creation: Fireball Archer installs via rundll32.exe and InstallArcherSvc
Flags rundll32.exe executions referencing InstallArcherSvc in the process command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2017-06-03Windows Registry Event: Pandemic implant key path contains null Instance
Detects registry activity targeting CurrentControlSet\services\null\Instance, associated with Windows implant persistence staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical81Free2017-06-01Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Alerts when RULER-labeled Windows Security events show NTLM auth (4776) plus 4624/4625 logons.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh297Free2017-05-31Windows Registry: DHCP Server Callout DLL and Enable Parameters Installation
Alerts on registry changes enabling and configuring DHCP Server callout DLLs via CalloutDlls and CalloutEnabled.
Dimitrios Slamaris, Huntrule TeamWindowsregistry_setHigh63Free2017-05-15