Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Bitbucket Global Secret Scanning Rule Deleted (Audit Logs)
Alerts on Bitbucket audit events indicating a global secret scanning rule was deleted.
Muhammad Faisal (@faisalusuf), Huntrule TeamBitbucketauditMedium112Free2024-02-25Bitbucket Audit: Global Permission Add/Remove/Request Events
Alerts on Bitbucket audit events indicating global permission changes being requested, granted, or removed.
Muhammad Faisal (@faisalusuf), Huntrule TeamBitbucketauditMedium436Free2024-02-25Bitbucket Audit: Full Data Export Triggered
Alerts when Bitbucket audit logging records a full data export being triggered.
Muhammad Faisal (@faisalusuf), Huntrule TeamBitbucketauditHigh151Free2024-02-25Windows Suspicious Wget.exe Downloads From IP to Common Staging Paths
Flags wget.exe on Windows downloading from an IP over HTTP and saving to common staging/user directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2024-02-23Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2024-02-23Windows SimpleService Execution via Remote Access Tool Wrapper Paths
Flags Windows processes running SimpleService.exe from remote access tool wrapper directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2024-02-23Windows Process Execution from ScreenConnect.ClientService.exe
Alerts on Windows process creation spawned by ScreenConnect.ClientService.exe, indicating potential remote command execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium50Free2024-02-23Windows File Events Indicative of SlashAndGrab ScreenConnect Post-Exploitation
Alerts on Windows file activity writing known SlashAndGrab-related ScreenConnect artifact paths and executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh193Free2024-02-23Windows: ScreenConnect local user database XML modified
Flags Windows file modifications by ScreenConnect.Service.exe to a Temp/ScreenConnect XML user database file.
Matt Anderson, Andrew Schwartz, Caleb Stewart, Huntress, Huntrule TeamWindowsfile_eventMedium208Free2024-02-21Windows DNS Queries to Known DPRK C2 Domains
Flags Windows DNS queries for specific DPRK-attributed C2 domain names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryHigh93Free2024-02-20ScreenConnect Service temp XML user database file modification (Windows Event 4663)
Alerts when ScreenConnect.Service.exe performs write access to temporary ScreenConnect XML user database files on Windows.
Matt Anderson, Kris Luzadre, Andrew Schwartz, Huntress, Huntrule TeamWindowssecurityMedium434Free2024-02-20Webserver Path Scan for ScreenConnect SetupWizard Authentication Bypass (CVE-2024-1709)
Alerts on web requests to '/SetupWizard.aspx/' that match exploitation patterns for ScreenConnect authentication bypass CVE-2024-1709.
Matt Anderson, Huntress, Huntrule Team—webserverCritical176Free2024-02-20Proxy Detection: Cobalt Strike Malleable C2 Profile HTTP URI/User-Agent/Method Patterns
Flags proxy HTTP requests whose URI, method, User-Agent, host, and cookie fragments match known Cobalt Strike malleable profile patterns.
Markus Neis, Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh3610Free2024-02-15Windows Module Usage Enumeration via tasklist.exe -m rdpcorets.dll
Flags tasklist.exe module enumeration (-m) targeting rdpcorets.dll to identify the owning process.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium152Free2024-02-12