Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Linux Process Execution of BarracudaMailService and Resize Utility Binaries
Alerts on Linux process creation for executables ending with three specific names linked to SEASPY deployment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationCritical141Free2023-06-16Windows Rundll32 Execution via Suspicious DLL Path Without .dll Extension
Alerts when rundll32.exe is started from suspicious parent scripts with a DLL-like path missing the .dll extension.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical156Free2023-05-24Windows Qakbot-associated Rundll32 execution via suspicious parent process and export strings
Flags rundll32.exe executions tied to Qakbot-style export strings when launched by script/cmd utilities.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical81Free2023-05-24Proxy HTTP GET to api.telegram.org with chat_id and text com/ (Small Sieve C2 behavior)
Alerts on proxy HTTP GET requests to api.telegram.org containing a specific chat_id and com/ prefix consistent with C2 behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyCritical112Free2023-05-19Windows Service Creation for Backdoor Persistence via GoogleUpdate (Event ID 7045)
Flags creation of a "GoogleUpdate" Windows service with rundll32/FileProtocolHandler image path pointing to ProgramData persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemCritical494Free2023-05-15Windows Service Creation for WerFaultSvc Using C:\Windows\WinSxS\WerFault.exe
Alerts on Windows service creation of WerFaultSvc pointing to C:\Windows\WinSxS\...\WerFault.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemCritical141Free2023-05-10Windows File Indicator: SNAKE Malware Kernel Driver Target File Comadmin.dat
Alerts on Windows file events involving C:\Windows\System32\Com\Comadmin.dat, an indicator tied to SNAKE kernel driver activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical243Free2023-05-10Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical415Free2023-05-04Windows Process Creation: svchost.exe with msupdate/alg Service Flags
Alerts on svchost.exe started with specific -k command-line flags consistent with suspicious persistence activity.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical153Free2023-04-30Windows rundll32 Cleanup Export Execution via msupdate Service Host (ColdSteel)
Flags svchost.exe msupdate-style services spawning rundll32.exe to run cleanup-related exports.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical151Free2023-04-30Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical150Free2023-04-20Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling
Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical110Free2023-04-20Windows: Rorschach execution indicator via critical command-line pattern
Windows process creation events with certain system utilities and a "11111111" command-line marker are flagged as ransomware execution activity.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical203Free2023-04-04Windows DLL Image Load Identified by Hashes for Compromised 3CXDesktopApp Components
Flags DLL loads in Windows when loaded module hashes match known compromised 3CXDesktopApp-related files.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadCritical2510Free2023-03-31Windows: Outlook querying WebClient/LanmanWorkstation registry network provider keys
Flags Outlook.exe querying HKLM\SYSTEM\Services WebClient/LanmanWorkstation NetworkProvider registry values.
Robert Lee @quantum_cookie, Huntrule TeamWindowssecurityCritical183Free2023-03-16