Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,164 rules
Windows: WinRM Service Process Spawning Command-Line and Scripting Utilities
Flags suspicious child shells and admin utilities spawned by the WinRM host process (wsmprovhost.exe) on Windows.
Andreas Hunkeler (@Karneades), Markus Neis, Huntrule TeamWindowsprocess_creationHigh293Free2021-05-20PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh2210Free2021-05-18AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
Alerts on CloudTrail ModifySnapshotAttribute events indicating EC2 snapshot permissions were changed for other-account access.
Darin Smith, Huntrule TeamAwscloudtrailMedium194Free2021-05-17Windows Process Command Lines Indicating ngrok.exe Tunnel Setup
Detects Windows executions of ngrok.exe with TCP/HTTP tunneling and authtoken/start-all YAML configuration patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh211Free2021-05-14Windows process creation patterns associated with DarkSide ransomware helpers
Detects Windows process creation consistent with DarkSide ransomware helper execution using encoded command-line content.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2021-05-14Webserver Indicators of Successful Exchange CVE-2021-28480 Exploitation via OWA Calendar POST
Flags POST requests to OWA calendar endpoint patterns linked to CVE-2021-28480, excluding HTTP 503 responses.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical162Free2021-05-14Windows: Detect Rclone command execution with exfiltration-oriented flags
Identifies likely rclone.exe exfiltration activity on Windows by matching command-line flags and rclone executable characteristics.
Bhabesh Raj, Sittikorn S, Aaron Greetham (@beardofbinary) - NCC Group, Huntrule TeamWindowsprocess_creationHigh133Free2021-05-10Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.
Bhabesh Raj, Huntrule TeamWindowssystemCritical3010Free2021-05-06Windows Driver File MoriyaStreamWatchmen.sys Created in System32\drivers
Alerts when the Windows system32 drivers directory receives the MoriyaStreamWatchmen.sys file.
Bhabesh Raj, Huntrule TeamWindowsfile_eventCritical141Free2021-05-06Windows whoami.exe Privilege Enumeration Using /priv Flag
Alerts on whoami.exe runs with /priv or -priv to enumerate current user privileges.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2021-05-05Linux Code Injection via ld.so Preload File (/etc/ld.so.preload)
Alerts on references to /etc/ld.so.preload, indicating possible dynamic-library injection persistence on Linux.
Christian Burkard (Nextron Systems), Huntrule TeamLinux—High367Free2021-05-05Windows Pingback backdoor via ICMP C2 using updata.exe command-line parameters
Flags Windows process creation where updata.exe spawns msdtc config start auto commands consistent with Pingback backdoor.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh92Free2021-05-05Windows DLL Loading of C:\Windows\oci.dll by msdtc.exe
Flags msdtc.exe loading C:\Windows\oci.dll, consistent with Pingback backdoor DLL loading behavior.
Bhabesh Raj, Huntrule TeamWindowsimage_loadHigh468Free2021-05-05Windows File Indicator for Pingback Backdoor updata.exe Writing oci.dll
Alerts on updata.exe creating or modifying C:\Windows\oci.dll as a Pingback backdoor file indicator.
Bhabesh Raj, Huntrule TeamWindowsfile_eventHigh224Free2021-05-05Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh386Free2021-05-03