Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,214 rules
Windows CMD dir /S File and Subfolder Enumeration
Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.
frack113, Huntrule TeamWindowsprocess_creationLow91Free2021-12-13PowerShell Script Block Collection of Browser Bookmarks via Get-ChildItem
Detects PowerShell Get-ChildItem activity used to recursively enumerate browser bookmarks from a target path.
frack113, Huntrule TeamWindowsps_scriptLow152Free2021-12-13Windows Process Discovery via wmic.exe "group" Flag
Flags wmic.exe process executions querying local group information via a "group" command-line argument.
frack113, Huntrule TeamWindowsprocess_creationLow298Free2021-12-12PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
frack113, Huntrule TeamWindowsps_scriptLow319Free2021-12-12PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
frack113, Huntrule TeamWindowsps_moduleLow111Free2021-12-12Webserver JNDI-Exploit-Kit Exploitation Indicators via Known Payload Paths
Flags webserver requests whose URL paths match known JNDI-Exploit-Kit exploit, deserialization, and memshell pattern strings.
Florian Roth (Nextron Systems), Huntrule TeamWebwebserverHigh162Free2021-12-12Windows Process Discovery via tasklist Command Execution
Alerts on Windows executions of tasklist.exe used for running process discovery.
frack113, Huntrule TeamWindowsprocess_creationInformational120Free2021-12-11Windows Process Creation: Nmap/Zenmap (nmap.exe or zennmap.exe) Execution
Flags Windows execution of Nmap/Zenmap (nmap.exe or zennmap.exe) used for remote service discovery.
frack113, Huntrule TeamWindowsprocess_creationMedium151Free2021-12-10Windows Net.exe Network Connections Discovery via Use Sessions Query
Flags net.exe/net1.exe commands using 'use sessions' to enumerate network connection/session information.
frack113, Huntrule TeamWindowsprocess_creationLow120Free2021-12-10Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Alerts when SharpView.exe runs with command-line indicators of AD and network discovery/enumeration activity.
frack113, Huntrule TeamWindowsprocess_creationHigh162Free2021-12-10PowerShell Get-NetTCPConnection Network Connection Discovery (Windows)
Detects PowerShell use of Get-NetTCPConnection to enumerate TCP network connections for discovery.
frack113, Huntrule TeamWindowsps_moduleLow101Free2021-12-10Windows PowerShell: Query TCP connections with Get-NetTCPConnection
Detects PowerShell usage of Get-NetTCPConnection to enumerate TCP network connections.
frack113, Huntrule TeamWindowsps_classic_startLow392Free2021-12-10Suspicious /dev/tcp Usage in Linux Shell Commands
Flags Linux shell commands containing suspicious /dev/tcp redirection and file descriptor constructs.
frack113, Huntrule TeamLinux—Medium405Free2021-12-10Webserver log detection of Log4j CVE-2021-44228 JNDI payloads in User-Agent, URI query, or Referer
Flags webserver requests with ${jndi:...} payloads in User-Agent, URI query, or Referer indicative of Log4Shell attempts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh285Free2021-12-10Webserver detection of Log4j RCE (CVE-2021-44228) JNDI injection patterns
Detects webserver traffic containing Log4Shell-style JNDI injection payload strings, excluding Nessus scan artifacts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh111Free2021-12-10