Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,194 rules
Okta Sign-On Policy Updated or Rule Deleted
Flags Okta sign-on policy updates and sign-on rule deletions in application policies.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium122Free2021-09-12Okta Application Lifecycle Update or Deletion Events
Alerts on Okta application updates and deletions based on application lifecycle event types in the System Log.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium132Free2021-09-12Okta: Detect API token revocation events
Flags Okta API token revocations using system.api_token.revoke System Log events.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium123Free2021-09-12Okta System API Token Creation Events
Flags Okta API token creation events to support investigation of potential persistence.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium343Free2021-09-12Okta Admin Role Granted to User or Group
Flags Okta privilege grant events that assign Administrator permissions to a user or group.
Austin Songer @austinsonger, Huntrule TeamOktaoktaMedium102Free2021-09-12Linux steghide steganography: Extract hidden files from JPG/PNG
Detects steghide extracting embedded data from image files (.jpg/.png) on Linux.
Pawel Mazur, Huntrule TeamLinuxauditdLow231Free2021-09-11Linux auditd: Steghide embeds hidden files via steghide embed with -cf/-ef
Flags steghide embed usage with -cf/-ef on Linux from auditd EXECVE events.
Pawel Mazur, Huntrule TeamLinuxauditdLow347Free2021-09-11Linux Commands Clearing or Removing /var/log/syslog
Flags Linux activity that clears, deletes, or redirects /var/log/syslog, a likely attempt to impair logging.
Max Altgelt (Nextron Systems), Huntrule TeamLinux—High123Free2021-09-10Zoho ManageEngine ADSelfService Plus CVE-2021-40539 REST API exploit URL access (Web)
Flags web requests targeting ADSelfService Plus REST API paths linked to CVE-2021-40539 authentication bypass.
Sittikorn S, Nuttakorn Tungpoonsup, Huntrule Team—webserverCritical110Free2021-09-10Windows Winword.exe Creates INetCache .cab and .inf Files During CVE-2021-40444 Exploitation
Flags winword.exe writing CABs in INetCache or INF files in Temp consistent with CVE-2021-40444 exploitation.
Florian Roth (Nextron Systems), Sittikorn S, Huntrule TeamWindowsfile_eventHigh161Free2021-09-10Linux auditd: Unzip files extracted from JPG/PNG images
Alerts when unzip is run against image files (.jpg/.png), consistent with extracting hidden data from steganographic containers.
Pawel Mazur, Huntrule TeamLinuxauditdLow102Free2021-09-09Linux auditd: cat appends ZIP data to image files
Alerts when cat is used to handle .jpg/.png with an associated .zip argument, consistent with hiding ZIP data in images.
Pawel Mazur, Huntrule TeamLinuxauditdLow101Free2021-09-09Windows Process Execution of control.exe Spawned by Office Apps Matching CVE-2021-40444 Pattern
Alerts when control.exe is launched from Office apps with suspicious DLL-related command lines, consistent with CVE-2021-40444 exploitation attempts.
Florian Roth (Nextron Systems), @neonprimetime, Huntrule TeamWindowsprocess_creationHigh122Free2021-09-08Windows Process Creation: Atlassian Confluence Java Spawns Suspicious Utility Child Processes (CVE-2021-26084)
Flags suspicious child processes spawned by Confluence’s Java on Windows, consistent with attempted CVE-2021-26084 exploitation.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh131Free2021-09-08Windows Image Load of clfsw32.dll by svchost.exe indicating PRIVATELOG usage
Alert on svchost.exe loading clfsw32.dll, a rarely observed Windows image load pattern consistent with PRIVATELOG.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2021-09-07