Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,266 rules
Windows: PSEXESVC-Launched Child Process Running as LOCAL SYSTEM
Alerts when PSEXESVC spawns a child process running as LOCAL SYSTEM (AUTHORI/AUTORI) on the local host.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh374Free2022-07-21Windows PsExec Service Binary Renamed Execution via psexesvc.exe
Alerts when psexesvc.exe is executed from a non-standard path, suggesting renamed or relocated PsExec service usage.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-07-21Windows Explorer ZIP Extraction Dropping Startup Folder Shortcut
Alert on explorer.exe writing Startup-folder LNK files whose names include {0AFACED1-E828-11D1-9187-B532F1E9575D}, indicating shortcut-based persistence.
Greg (rule), Huntrule TeamWindowsfile_eventHigh71Free2022-07-21Linux Process Command-Line Indicators of Apache Spark Shell Command Injection Attempt
Alerts on Linux process creation where a bash-spawned command line contains `id -Gn ` injection-like backtick or quote patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh267Free2022-07-20Webserver User-Agent Identifies Known Recon and Scanning Tool Strings
Alerts on web requests with User-Agent values containing known recon/scanner tool identifiers.
Nasreddine Bencherchali (Nextron Systems), Tim Shelton, Huntrule TeamWebwebserverMedium103Free2022-07-19Azure App/Service Principal Assigned to Entra ID or Azure RBAC Roles (Audit Logs)
Finds Azure role assignments where an app/service principal is granted, eligible, or scoped membership via audit log messages.
Bailey Bercik '@baileybercik', Mark Morowczynski '@markmorow', Huntrule TeamAzureauditlogsMedium174Free2022-07-19Azure Entra conditional access policy updated by non-approved actor
Alerts when an Azure Entra Conditional Access policy update occurs, indicating access control changes by an actor outside the approved set.
Corissa Koopmans, '@corissalea', Huntrule TeamAzureauditlogsMedium71Free2022-07-19Azure Entra Conditional Access Policy Deleted by Non-Approved Actor
Flags Azure audit log events where a conditional access policy is deleted.
Corissa Koopmans, '@corissalea', Huntrule TeamAzureauditlogsMedium359Free2022-07-19Weblog Detection of Apache Spark Shell Command Injection Payloads (?doAs=`)
Alerts on web requests containing "?doAs=`" that may indicate Spark shell command injection attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh112Free2022-07-19Rejetto HFS HTTP request RCE exploit pattern via null-byte search and script/command payloads
Detects Rejetto HFS HTTP requests with a crafted search parameter and command/script execution indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh278Free2022-07-19Windows UEFI Persistence: Detect wpbbin.exe Execution
Alerts on execution of C:\Windows\System32\wpbbin.exe, a potential indicator of UEFI persistence on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-07-18Windows UEFI Persistence Indicator: Creation of C:\Windows\System32\wpbbin.exe
Flags creation of C:\Windows\System32\wpbbin.exe, a potential UEFI persistence artifact.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh442Free2022-07-18Azure Conditional Access Policy Added by Non-approved Actor
Alerts on Azure audit log events indicating a Conditional Access policy was added.
Corissa Koopmans, '@corissalea', Huntrule TeamAzureauditlogsMedium123Free2022-07-18Windows Registry Fax Device Provider ImageName changed to load external DLL
Alerts when Fax Device Providers\ImageName registry values change in a way consistent with DLL-loading persistence.
frack113, Huntrule TeamWindowsregistry_setHigh103Free2022-07-17Windows Registry: User Account Changed for FAX Service
Flags registry changes that alter the FAX service’s associated user account on Windows.
frack113, Huntrule TeamWindowsregistry_setHigh245Free2022-07-17