Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Palo Alto GlobalProtect PAN-OS Device Telemetry File Creation with Command Injection Filename Markers
Detects suspicious GlobalProtect device telemetry file creations with filenames containing CVE-2024-3400 command-injection indicators.
Andreas Braathen (mnemonic.io), Huntrule TeamPaloaltofile_eventMedium81Free2024-04-25Windows Registry Set: Custom Protocol Handler DLL for CLSID {026CC6D7-34B2-33D5-B551-CA31EB6CE345}
Alerts when a Windows registry entry for a specific custom protocol handler CLSID is set to a DLL.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh104Free2024-04-23Windows Process Creation: Forest Blizzard-related hashes and scheduled task activity
Detects suspicious Windows process execution tied to known hashes or schtasks/PowerShell command-line patterns used for staging and compression.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2024-04-23Windows JavaScript file creation in DriverStore FileRepository
Alerts on creation of .js files under DriverStore\FileRepository based on the target path in Windows file events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium3910Free2024-04-23Windows File Creation: ProgramData Persistence Artifacts Matching
Alerts on Windows file creations in C:\ProgramData matching specific driver inf, .dll, and batch/script filename patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh142Free2024-04-23Suspicious Palo Alto GlobalProtect Session Unmarshal Path Traversal and Command Injection Attempts
Detects GlobalProtect logs with directory traversal/command injection-style indicators tied to CVE-2024-3400 behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamPaloaltoapplianceHigh121Free2024-04-18Cisco Duo MFA Success Triggered by Admin-Assigned Bypass Code
Alert on Duo successful MFA logins that are attributed to bypass-user codes.
Nikita Khalimonenkov, Huntrule TeamCiscoduoMedium206Free2024-04-17Linux Pnscan Binary Data Transfer via Command-Line
Flags Linux executions with Pnscan-like arguments indicating binary send/receive data transfer.
David Burkett (@signalblur), Huntrule TeamLinuxprocess_creationMedium102Free2024-04-16Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh459Free2024-04-15Kubernetes API Audit: Unauthorized (401) or Forbidden (403) Access Attempts
Alerts on Kubernetes API audit events returning 401 or 403, indicating authentication or authorization failures.
kelnage, Huntrule TeamKubernetesauditLow442Free2024-04-12Linux sshd Spawns Root Shell Script Commands Suggesting CVE-2024-3094 Exploitation
Alerts on sshd spawning bash/sh one-liners as root, a potential indicator of CVE-2024-3094 style exploitation.
Arnim Rupp, Nasreddine Bencherchali, Thomas Patzke, Huntrule TeamLinuxprocess_creationHigh193Free2024-04-01Azure AD Audit: Trusted Root CA Added for Passwordless Certificate Authentication
Alerts on Azure AD changes that add a new trusted root CA for passwordless certificate-based authentication.
Harjot Shah Singh, '@cyb3rjy0t', Huntrule TeamAzureauditlogsMedium131Free2024-03-26Azure AD Audit Logs: Certificate-based authentication enabled via AuthenticationMethodsPolicy update
Flags Azure AD audit log events where the Authentication Methods policy is updated to enable certificate-based authentication.
Harjot Shah Singh, '@cyb3rjy0t', Huntrule TeamAzureauditlogsMedium256Free2024-03-26Kubernetes Audit: Sidecar Injection via kubectl patch to Deployments
Detects PATCH operations against Kubernetes Deployments that may indicate sidecar-style container injection.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationMedium252Free2024-03-26Kubernetes Service Account Created via Audit Log
Alerts on Kubernetes audit events showing new ServiceAccounts created.
Leo Tsaousis (@laripping), Huntrule TeamKubernetesapplicationLow431Free2024-03-26