Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,161 rules
Windows rundll32 Executing Inline VBScript via RegRead
Detects rundll32.exe command lines containing inline VBScript execution with RegRead and window.close.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh378Free2021-03-05Windows Process Command Line: Suspicious Inline VBScript with UN2452-Like Keywords
Alerts on Windows command lines containing inline VBScript keywords and registry access indicators matching the UNC2452 UN2452 pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2021-03-05Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Flags PowerShell executions that Add-PSSnapin Exchange snap-ins, consistent with Exchange mailbox/config data collection.
FPT.EagleEye, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh286Free2021-03-03Windows PowerShell TcpClient reverse-shell connection attempt via Net.Sockets
Alerts on PowerShell processes launching with .NET TcpClient stream/write patterns consistent with reverse TCP connectivity.
FPT.EagleEye, wagga, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2021-03-03Microsoft Exchange exploitation attempt via suspicious POST requests in web server logs
Flags POST traffic to Exchange OWA/ECP-related URLs with specific client and user-agent indicators consistent with exploitation attempts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh314Free2021-03-03Windows Exchange UMWorkerProcess File Drops Indicating CVE-2021-26858 Exploitation
Alerts on Exchange Unified Messaging (UMWorkerProcess.exe) creating unusual files, excluding common benign names consistent with CVE-2021-26858 activity.
Bhabesh Raj, Huntrule TeamWindowsfile_eventHigh433Free2021-03-03Windows Process Creation: Suspected CVE-2021-26857 Exploitation via UMWorkerProcess.exe
Detects suspicious child process spawning by Exchange Unified Messaging (UMWorkerProcess.exe) associated with CVE-2021-26857 attempts.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh288Free2021-03-03Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical123Free2021-02-26Windows Process Creation: finger.exe Execution
Alerts on Windows executions of finger.exe, a legacy utility that may indicate suspicious reconnaissance or network activity.
Florian Roth (Nextron Systems), omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh93Free2021-02-24Webserver POST to vROps uploadova endpoint indicative of CVE-2021-21972 exploitation
Alerts on POST requests to the uploadova endpoint tied to CVE-2021-21972 vSphere exploitation.
Bhabesh Raj, Huntrule Team—webserverHigh141Free2021-02-24Webserver URI Detects DEWMODE Webshell Access Attempts
Identifies webserver requests with DEWMODE webshell-specific URI query parameter patterns.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh122Free2021-02-22Windows ScreenConnect Installation Execution via Remote Access Parameters
Flags Windows executions of ScreenConnect with remote access command-line parameters indicating remote session setup.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2021-02-11Windows Process Creation: logman.exe Used to Stop or Delete ETW Trace Sessions
Alerts when logman.exe is used to stop or delete Windows ETW trace sessions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2110Free2021-02-11Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Detects AdFind executions on Windows that include common AD reconnaissance parameters.
Janantha Marasinghe (https://github.com/blueteam0ps), FPT.EagleEye Team, omkar72, oscd.community, Huntrule TeamWindowsprocess_creationHigh50Free2021-02-02Windows Audit Policy Tampering Using auditpol.exe Command-Line Flags
Flags auditpol.exe executions that disable, clear, remove, or restore Windows audit policy settings.
Janantha Marasinghe (https://github.com/blueteam0ps), Huntrule TeamWindowsprocess_creationHigh299Free2021-02-02