Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,169 rules
Antivirus detections of PrinterNightmare PoC file creation path on Windows
Alerts on antivirus events where filenames include the Windows spooler driver x64 directory path, excluding Symantec submission messages.
Sittikorn S, Nuttakorn T, Tim Shelton, Huntrule Team—antivirusCritical469Free2021-07-01Windows SMB Client Security: Rejected Guest Logon with Blank UserName
Flags rejected SMB guest/anonymous-style logons on Windows when the SMB username is blank.
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Huntrule TeamWindowssmbclient-securityMedium248Free2021-06-30Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Looks for Print Spooler plug-in/module load errors in Windows logs that may indicate CVE-2021-1675 exploitation attempts.
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Tim Shelton, Huntrule TeamWindowsprintservice-adminHigh331Free2021-06-30Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
Wojciech Lesicki, Huntrule TeamWindowsregistry_setHigh223Free2021-06-29AWS EC2: DisableEbsEncryptionByDefault API call to turn off default EBS encryption
Flags when EC2 default EBS encryption is disabled for the current AWS region via CloudTrail.
Sittikorn S, Huntrule TeamAwscloudtrailMedium275Free2021-06-29Pulse Connect Secure web exploitation attempts for CVE-2021-22893
Detects web requests to Pulse Connect Secure with URI query patterns consistent with CVE-2021-22893 exploitation attempts.
Sittikorn S, Huntrule Team—webserverHigh446Free2021-06-29Windows ImageLoad of DLL from spoolsv.exe spool drivers subfolders
Flags spoolsv.exe DLL loads originating from Print Spooler x64\3/x64\4 driver folders on Windows.
FPT.EagleEye, Thomas Patzke (improvements), Huntrule TeamWindowsimage_loadInformational307Free2021-06-29Windows File Events: PoC Filename Pattern for CVE-2021-1675 Spooler Exploitation
Flags Windows file events referencing a specific spooler driver path pattern associated with CVE-2021-1675 PoC activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical241Free2021-06-29Windows reg.exe Run Key Modification for Persistence via Process Creation
Alerts on reg.exe commands that add values to Windows Run registry keys, a common persistence technique.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium130Free2021-06-28AWS CloudTrail: Security Hub findings evasion via finding updates or deletions
Identifies Security Hub finding and insight modifications (update or delete) that may impair detection results.
Sittikorn S, Huntrule TeamAwscloudtrailHigh172Free2021-06-28Windows Process Creation: WMIC.exe ActiveScriptEventConsumer Creation Attempt
Alerts on WMIC.exe command lines attempting to create an ActiveScriptEventConsumer for event-driven script execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh484Free2021-06-25Zeek x509: Default Cobalt Strike certificate serial observed in HTTPS traffic
Flags Zeek x509 certificates used in HTTPS when the certificate serial matches a known default Cobalt Strike value.
Bhabesh Raj, Huntrule TeamZeekx509High182Free2021-06-23Windows PortProxy Registry Key Modified for Port Forwarding
Alerts when PortProxy port-forwarding registry entries under the Windows TCP v4tov4 path are added or modified.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_eventMedium443Free2021-06-22Windows: Detect execution of renamed megasync.exe (original MegaSync) via process creation
Flags process launches where megasync.exe appears under a renamed or nonstandard execution context based on process creation fields.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh4610Free2021-06-22Windows LDAP Client Event ID 30 Active Directory enumeration via LDAP search filters
Flags LDAP search queries indicative of Active Directory reconnaissance/enumeration using Event ID 30 filter patterns.
Adeem Mawani, Huntrule TeamWindowsldapMedium429Free2021-06-22