Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,249 rules
Windows Process Creation: Suspicious PowerShell Child of Tomcat prunsrv.exe (CVE-2022-22954 Attempt)
Alerts when prunsrv.exe spawns PowerShell or cmd.exe running PowerShell, consistent with potential Workspace ONE Access RCE attempts.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium161Free2022-04-25Windows msiexec.exe Command Line Loading a DLL and Calling DllUnregisterServer
Alert when msiexec.exe runs with -z and a .dll on the command line, consistent with DLL DllUnregisterServer execution.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2022-04-24PowerShell WMI Win32_Product MSI Installation via Invoke-CimMethod
Flags PowerShell using WMI Win32_Product via Invoke-CimMethod to invoke an MSI install.
frack113, Huntrule TeamWindowsps_scriptMedium91Free2022-04-24Windows: File Creation of Get-Variable.exe in PowerShell WindowsApps Path
Alerts on creation of Get-Variable.exe in Local\Microsoft\WindowsApps, a potential cmdlet-path hijack.
frack113, Huntrule TeamWindowsfile_eventHigh162Free2022-04-23Windows Remote Thread Created in KeePass.exe
Flags remote thread creation targeting KeePass.exe, a possible indicator of credential theft.
Timon Hackenjos, Huntrule TeamWindowscreate_remote_threadHigh93Free2022-04-22Windows: Emotet .LNK Loader Execution via cmd.exe or PowerShell
Alerts on cmd/powershell-launched commands referencing findstr, a .vbs script, and a .lnk file—indicative of shortcut-triggered loader activity.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh121Free2022-04-22Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Alerts on rundll32 launching the Windows Key Manager (keymgr / KRShowKeyMgr), a potential credential access step.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-04-21Zeek DNS: Detect NKN Seed Domain Queries
Alerts on Zeek DNS queries containing "seed" and ending with .nkn.org, a pattern consistent with NKN network activity.
Michael Portera (@mportatoes), Huntrule TeamZeekdnsLow132Free2022-04-21Windows process contacting Dropbox API from non-Dropbox executables
Alerts when a non-Dropbox executable makes initiated connections to Dropbox API endpoints on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh91Free2022-04-20Windows Process Execution via 7zFM.exe Indicative of CVE-2022-29072 Exploitation
Alerts when 7zFM.exe spawns cmd.exe or PowerShell with command-line patterns consistent with CVE-2022-29072 exploitation attempts.
frack113, @kostastsale, Huntrule TeamWindowsprocess_creationHigh383Free2022-04-17Windows Process Creation: msiexec.exe Embedding Spawned by PowerShell/cmd/pwsh
Alerts when cmd/powershell launches msiexec.exe with -Embedding, a proxy execution pattern.
frack113, Huntrule TeamWindowsprocess_creationMedium102Free2022-04-16Linux cron: Suspicious crontab modification with REPLACE
Alerts on Linux cron activity indicating crontab changes containing the keyword "REPLACE".
Pawel Mazur, Huntrule TeamLinuxcronMedium131Free2022-04-16Windows Registry: Delete SD Value Under Schedule\TaskCache\Tree to Impair Scheduled Task Visibility
Detects deletion of the SD registry value under Schedule\TaskCache\Tree, which can impair scheduled task visibility.
Sittikorn S, Huntrule TeamWindowsregistry_deleteMedium142Free2022-04-15Windows schtasks.exe scheduled task creation from suspicious folders
Alerts on schtasks.exe /create using PowerShell/cmd and suspicious folder paths like ProgramData.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh404Free2022-04-15Windows Network Connections Initiated by Eqnedt32.EXE
Identifies outbound network connections started by eqnedt32.exe on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh132Free2022-04-14