Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,159 rules
Windows rundll32.exe Command-Line RunDLL or Control_RunDLL Execution
Alerts on rundll32.exe process launches whose command lines end with RunDLL/Control_RunDLL, indicative of DLL function loading.
FPT.EagleEye, Huntrule TeamWindowsprocess_creationCritical201Free2020-12-25Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution
Alerts on Windows process executions with command-line substrings consistent with behaviors described in Lazarus activity reports.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowsprocess_creationCritical4110Free2020-12-23Detect SolarWinds SUPERNOVA Webshell URL Access on Webservers (logoimagehandler.ashx)
Identifies webserver traffic consistent with SUPERNOVA webshell access targeting logoimagehandler.ashx with a clazz query parameter.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical334Free2020-12-17Windows: Suspicious Child Processes Spawned by sqlservr.exe
Alerts when SQL Server (sqlservr.exe) spawns suspicious command/system tools on Windows.
FPT.EagleEye Team, wagga, Huntrule TeamWindowsprocess_creationHigh157Free2020-12-11Fortinet SSL VPN Exploitation Attempt via Path Traversal in Web Requests (CVE-2018-13379)
Alerts on HTTP requests matching a Fortinet SSL VPN traversal-style query indicative of CVE-2018-13379 exploitation.
Bhabesh Raj, Huntrule Team—webserverCritical141Free2020-12-08Windows Process Tree: rundll32.exe launching wermgr.exe via DllRegisterServer
Flags rundll32.exe spawning wermgr.exe where rundll32 command line includes DllRegisterServer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2020-11-26Web server request pattern consistent with Oracle WebLogic CVE-2020-14882 exploitation
Detects WebLogic console exploitation attempts by matching encoded traversal patterns in HTTP URI query strings.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh329Free2020-11-02Windows Registry Run Key Modification via winekey or team9 backdoor
Detects registry Run key changes to "Backup Mgr" that may indicate persistence via winekey/team9.
omkar72, Huntrule TeamWindowsregistry_eventHigh151Free2020-10-30Windows PsExec Execution Triggered by psexec.exe Process Creation
Flags process creation of PsExec (psexec.exe / psexec.c), a tool often used for remote execution and potential lateral movement.
omkar72, Huntrule TeamWindowsprocess_creationMedium185Free2020-10-30Windows Credential Access via Reg Add in LSA Registry Paths
Alerts when reg add commands target LSA registry settings and scecli entries commonly abused for credential access.
Sreeman, Huntrule TeamWindowsprocess_creationMedium93Free2020-10-29Windows Process Creation: bitsadmin.exe BITS jobs with SetNotifyCmdLine or remote file additions
Alerts on bitsadmin.exe command lines using /SetNotifyCmdLine or /Addfile to execute after download or stage remote files.
Sreeman, Huntrule TeamWindowsprocess_creationMedium162Free2020-10-29Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh323Free2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventHigh152Free2020-10-29Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
Semanur Guneysu @semanurtg, oscd.community, Huntrule TeamWindowsprocess_creationHigh101Free2020-10-28Windows Registry Persistence via Office Test Startup Key
Flags registry changes to a Windows Office test startup key that may enable auto-execution of an arbitrary DLL.
omkar72, Huntrule TeamWindowsregistry_eventMedium456Free2020-10-25