Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,362 rules
Windows IIS appcmd Creating GlobalRules URL Rewrite Configuration
Flags appcmd.exe commands that modify IIS global URL rewrite globalRules and commit the configuration.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium131Free2023-01-22Windows Capability Added via PowerShell Add-WindowsCapability (OpenSSH)
Flags PowerShell commands that add Windows capabilities, specifically OpenSSH, via Add-WindowsCapability in logged script blocks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium166Free2023-01-22Windows PowerShell Active Directory Module Import for Enumeration
Detects PowerShell importing Microsoft.ActiveDirectory.Management.dll with Import-Module, often seen during AD enumeration.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsps_scriptMedium82Free2023-01-22Windows PowerShell AD Module DLL Import for Active Directory Enumeration
Flags PowerShell importing Microsoft.ActiveDirectory.Management.dll via Import-Module, a common step in AD discovery and enumeration.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleMedium152Free2023-01-22Windows: Detect Aruba Netsvc DLL Search Order Hijacking via arubanetsvc.exe Loaded DLLs
Flags arubanetsvc.exe loading targeted DLLs outside standard system paths, suggesting possible DLL search order hijacking.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh374Free2023-01-22Windows: OneNote .one/.onepkg File Creation in Suspicious Locations
Flags creation of OneNote attachment files (.one/.onepkg) in temp/public-style paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium337Free2023-01-22Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Detects rundll32 executions that reference DLLs stored in Alternate Data Streams via ADS-style paths.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamWindowsprocess_creationHigh103Free2023-01-21Windows PsExec Remote Execution Creates PSEXEC-*.key File Artefact
Alerts on creation of PsExec key files in C:\Windows\PSEXEC-*.key, indicating remote execution activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3010Free2023-01-21Windows Process Creation: svchost DHCPServer RCE Exploitation Attempt
Alerts on svchost.exe running as Network Service with -k DHCPServer, suggesting a potential pre-auth Windows RCE attempt.
Florian Roth (Nextron Systems), Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationHigh262Free2023-01-21Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Alerts on PowerShell module payloads containing commandlet/function names from known malicious exploitation and post-exploitation frameworks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_moduleHigh132Free2023-01-20GitHub Audit: Outside Collaborator Membership and Permission Changes
Alerts on GitHub audit events involving outside collaborators being removed or permission changes on projects.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditMedium103Free2023-01-20GitHub audit: New Actions secret created for org, environment, repo, or Codespaces
Triggers on GitHub audit events when an actor creates a new Actions secret for org, environment, Codespaces, or repo.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditLow229Free2023-01-20Detect CentOS Web Panel POST login reverse-shell RCE attempts (CVE-2022-44877)
Alert on POST requests to CentOS Web Panel login that contain command-execution and reverse-shell style query parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh221Free2023-01-20Windows driverquery.exe Process Execution Detection
Alerts on Windows executions of driverquery.exe (drvqry.exe) used to enumerate installed drivers, with parent-process exclusions to reduce duplicates.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2023-01-19Windows: driverquery.exe Usage for Installed Driver Recon
Alerts when driverquery.exe (drvqry.exe) is launched by script-based parent processes to enumerate installed drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2023-01-19