Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,438 rules
Windows: VMwareToolBoxCmd.exe script/set Used to Configure VM State Persistence
Flags VMwareToolBoxCmd.exe use of 'script' and 'set' parameters consistent with VM state–based persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-06-14Windows DLL Sideloading: waveedit.dll Loaded by Nero WaveEditor
Alerts when waveedit.dll is loaded from an unexpected path, suggesting possible DLL sideloading on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh155Free2023-06-14Potential GeoServer SQLi Probe for CVE-2023-25157 via OWS CQL_FILTER
Alerts on GET requests to GeoServer OWS with CQL_FILTER containing SQLi-style payload markers and functions.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh103Free2023-06-14Windows Registry: ClickOnce Trust PromptingLevel Set to Enabled for Multiple Locations
Alerts on Enabled ClickOnce trust prompting registry changes for Internet and related locations.
"@SerkinValery, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsregistry_setMedium101Free2023-06-12Suspicious Child Process Spawned by ClickOnce Application (Windows)
Alerts when a ClickOnce app under AppData\Local\Apps\2.0\ spawns common script/tool executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-06-12Windows ClickOnce Execution: dfsvc.exe Child Process Launch
Flags ClickOnce-style child processes spawned by dfsvc.exe from the AppData\Local\Apps\2.0\ directory on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-06-12dfsvc.exe Initiated Network Connection to Uncommon Ports (Windows)
Alerts on dfsvc.exe-initiated outbound connections targeting non-standard ports on Windows, excluding typical 80/443 and IPv6 DNS(53).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh70Free2023-06-12dfsvc.exe Initiated Network Connections to External (Non-Local) IPs on Windows
Alerts on dfsvc.exe initiating outbound connections to IPs outside local/private and link-local ranges.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium60Free2023-06-12Windows: Uncommon Child Processes Spawned by SndVol.exe
Alerts when SndVol.exe launches unusual child processes, using Windows process creation logs.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-06-09Windows: Potential RjvPlatform.dll DLL Sideloading via SystemResetPlatform.exe from Non-Default Path
Flags SystemResetPlatform.exe loading RjvPlatform.dll from a non-default location, indicating possible DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh171Free2023-06-09Windows: RjvPlatform.dll loaded by SystemResetPlatform.exe from $SysReset path
Alerts on SystemResetPlatform.exe loading RjvPlatform.dll from the $SysReset Framework Stack path on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium2210Free2023-06-09Windows DLL Sideloading Suspicion via edputil.dll Image Load
Alerts on edputil.dll image loads occurring outside standard Windows system directories, suggesting possible DLL side-loading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh112Free2023-06-09Windows DLL Sideloading Indicators: 7za.dll Loaded from Non-Program Files Paths
Alerts when a process loads 7za.dll from a non-Program Files path, indicating potential DLL sideloading.
X__Junior, Huntrule TeamWindowsimage_loadLow186Free2023-06-09Linux sshd Logs: Flag Failed Curve25519 Key Generation Indicative of libSSH CVE-2023-2283 Attempts
Alerts on sshd log entries with 'Failed to generate curve25519 keys' that may indicate CVE-2023-2283 libssh bypass attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsshdMedium2710Free2023-06-09Windows ClickOnce Loads Unsigned or Expired Signed Modules from User Apps Path
Alerts when a ClickOnce app loads a module from Apps\2.0 that is unsigned or has an expired signature.
"@SerkinValery, Huntrule Team"Windowsimage_loadMedium258Free2023-06-08