Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,193 rules
Microsoft Exchange ProxyToken Exploitation via ECP POST and InboxRules NewObject (CVE-2021-33766)
Flags POSTs to Exchange ECP InboxRules endpoints with SecurityToken= that return HTTP 500, indicating ProxyToken exploitation attempts.
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule Team—webserverCritical141Free2021-08-30Windows Process Creation Matching TrustedPath UAC Bypass Directory Mocking Strings
Alerts on Windows processes referencing System32/SysWOW64 paths consistent with TrustedPath UAC bypass directory mocking.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical132Free2021-08-27Exchange Management: Removal of Mailbox Export Request via Remove-MailboxExportRequest
Detects Exchange management removals of mailbox export requests using Remove-MailboxExportRequest with Confirm set to "False".
Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh81Free2021-08-27Windows Security: Suspicious Registry Access to ADHealthAgent Health Service Agent Keys
Detects non-standard processes accessing HKLM\SOFTWARE\Microsoft\ADHealthAgent registry key activity in Windows security logs.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamWindowssecurityMedium60Free2021-08-26Windows Security: Access to Azure AD Health Monitoring Agent Registry Key
Flags suspicious access to the Azure AD Health Monitoring Agent registry key using Windows Security 4656/4663.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamWindowssecurityMedium60Free2021-08-26Google Workspace: Admin audit events where strong authentication is allowed without enforcement (MFA disabled)
Alerts on Google Workspace admin changes that set strong authentication/MFA enforcement to false.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium472Free2021-08-26Google Workspace Admin: Application Removed from Domain
Flags Google Workspace domain events indicating an application was removed, including allowlist/whitelist removal.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium123Free2021-08-26Azure AD Hybrid Health AD FS Service Deletion via Azure Activity Logs
Flags Azure AD Hybrid Health AD FS service deletions from Azure Activity Logs under the Administrative category.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamAzureactivitylogsMedium151Free2021-08-26Azure Activity Logs: AD Hybrid Health AD FS server instance create/update
Alerts on Administrative Azure Activity Log events adding/updating AD Hybrid Health AD FS service member servers.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC, Huntrule TeamAzureactivitylogsMedium1910Free2021-08-26MODX Manager Path Traversal Attempt via tvs.php class_key (CVE-2010-5278)
Alerts on HTTP requests to MODx tvs.php with traversal-based class_key payload indicative of LFI attempts.
Subhash Popuri (@pbssubhash), Huntrule Team—webserverCritical161Free2021-08-25Google Workspace Admin: Detect Role Privilege Deletion (REMOVE_PRIVILEGE)
Triggers on Google Workspace role privilege removal events (REMOVE_PRIVILEGE) in Admin audit logs.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium102Free2021-08-24Google Workspace Admin Role Modified or Deleted via admin.googleapis.com Audit Events
Identifies Google Workspace role updates, renames, or deletions from admin.googleapis.com audit events.
Austin Songer, Huntrule TeamGcpgoogle_workspace.adminMedium279Free2021-08-24Web Exploitation of Arcadyan Router Path Traversal and Config Injection Attempts
Detects Arcadyan router exploit traffic by matching URL-encoded path traversal patterns in query strings linked to config injection.
Bhabesh Raj, Huntrule Team—webserverCritical389Free2021-08-24Windows Registry UAC Bypass Attempt via Windows Media Player osk.exe AppCompatFlags
Identifies registry AppCompatFlags entries for Windows Media Player osk.exe that may indicate a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2021-08-23Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
Vadim Khrykov (ThreatIntel), Cyb3rEng, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh396Free2021-08-23