Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,198 rules
Clipboard Data Collection via xclip (auditd Linux EXECVE)
Alerts on xclip command lines that request clipboard/clip selection output (-o) on Linux systems monitored by auditd.
Pawel Mazur, Huntrule TeamLinuxauditdLow123Free2021-09-24VMware vCenter Server file upload exploitation attempt for CVE-2021-22005 via POST telemetry endpoint
Identifies POST requests targeting a vCenter telemetry upload endpoint consistent with CVE-2021-22005 exploitation attempts.
Sittikorn S, Huntrule Team—webserverHigh82Free2021-09-24AWS CloudTrail: Lambda Function Updated with New Layer Attached
Flags CloudTrail UpdateFunctionConfiguration calls that attach Lambda layers to an existing function.
Austin Songer, Huntrule TeamAwscloudtrailLow142Free2021-09-23AWS CloudTrail Alert for Suspicious SAML Role Assumption and SAML Provider Updates
Flags CloudTrail activity involving SAML provider updates plus SAML role assumptions in AWS, which can enable backdoor access.
Austin Songer, Huntrule TeamAwscloudtrailMedium325Free2021-09-22PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsps_scriptHigh163Free2021-09-21Linux Import Tool Image Capture via execve with -window root and .png/.jpg output
Flags Linux ImageMagick import executions likely used for desktop screenshot capture to PNG/JPG outputs or root window.
Pawel Mazur, Huntrule TeamLinuxauditdLow1710Free2021-09-21Okta MFA Deactivation or Full Factor Reset Event Detection
Flags Okta events indicating MFA deactivation or reset_all actions by a user or actor.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium387Free2021-09-21Azure Activity Logs: New CloudShell Created via Microsoft.Portal Consoles Write
Alerts on Azure portal activity indicating a Cloud Shell console was created.
Austin Songer, Huntrule TeamAzureactivitylogsMedium451Free2021-09-21Windows: Xwizard.exe Execution from Non-Default Directory
Alerts when Xwizard.exe starts from an unexpected Windows path, indicating potential misuse or side-loading.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh455Free2021-09-20Detect suspicious AD SelfService web requests targeting report generation and API endpoints
Flags web requests with URL query strings targeting known ADSelfService exploitation paths for CVE-2021-40539.
Tobias Michalski (Nextron Systems), Max Altgelt (Nextron Systems), Huntrule Team—webserverHigh60Free2021-09-20Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Alert on HTTP 200 POST /wsman with no Authorization header and a non-empty body in Zeek logs, consistent with OMIGOD unauthenticated RCE attempts.
Nate Guagenti (neu5ron), Huntrule TeamZeekhttpHigh296Free2021-09-20PowerShell Add-DnsClientNrptRule Modifies NRPT Namespaces
Flags PowerShell scripts that add DNS Name Resolution Policy Table rules for a specified namespace.
Borna Talebi, Huntrule TeamWindowsps_scriptHigh162Free2021-09-14Linux screen capture using xwd saving a .xwd file
Flags xwd screen capture executions that write captured output to a .xwd file on Linux.
Pawel Mazur, Huntrule TeamLinuxauditdLow153Free2021-09-13Okta User Account Lockout Triggered by Max Sign-In Attempts
Flags Okta user account lockouts triggered by exceeding the max sign-in attempts threshold.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium152Free2021-09-12Okta: Unauthorized App Access Attempt Based on System Log Message
Alerts when Okta logs show a user attempted unauthorized access to an app.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium363Free2021-09-12