Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Proxy HTTP GET to /api/Core/Command Init/Restart indicative of possible C2
Flags proxy HTTP GET requests to C2-like command initialization/restart endpoints based on URI suffixes.
X__Junior (Nextron Systems), Huntrule Team—proxyMedium279Free2024-01-15Windows process creation matching specific Peach Sandstorm command-line indicator
Alerts on Windows process creations whose command line contains a specific suspicious substring.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2024-01-15GCP Google Workspace: Application ContextAwareAccess Setting Changed
Alerts on Google Workspace application setting changes affecting ContextAwareAccess access levels.
Bryan Lim, Huntrule TeamGcpgoogle_workspace.adminMedium152Free2024-01-12GCP Audit: Break-glass Keyword on Kubernetes Pod Create Overrides Binary Authorization
Flags GKE pod creation events where break-glass bypasses Binary Authorization image policy.
Bryan Lim, Huntrule TeamGcpgcp.auditMedium252Free2024-01-12GCP Audit Logs: Access Context Manager Access Policy Deletion
Flags GCP Access Context Manager audit events where granted access policy delete permissions occur.
Bryan Lim, Huntrule TeamGcpgcp.auditMedium368Free2024-01-12Windows: Detect renamed PingCastle binary execution via PE metadata and scanner command-line
Flags Windows processes that look like renamed PingCastle executables using PE original file names and PingCastle scanner/healthcheck arguments.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh179Free2024-01-11Windows PingCastle Execution From Suspicious Parent Processes
Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2024-01-11Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Alerts on Windows execution of PingCastle with full healthcheck and AD/security scanner command-line options.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium142Free2024-01-11Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
Alerts on Windows loading of .cpl control panel items from uncommon paths instead of standard system directories.
Anish Bogati, Huntrule TeamWindowsimage_loadHigh284Free2024-01-09Windows WFP 5157: Connection Blocked for EDR Agent Binaries
Flags WFP blocked connections (EventID 5157) when an EDR/security agent binary is the blocked application.
"@gott_cyber, Huntrule Team"WindowssecurityHigh263Free2024-01-08Windows forfiles.exe Spawned cmd.exe from Non-System Location
Alerts on forfiles.exe running outside system paths and spawning cmd.exe with a forfiles-encoded command pattern.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsprocess_creationHigh438Free2024-01-05Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Alerts on Windows Filtering Platform policy change events containing "RonPolicy" consistent with NoFilter abuse.
Stamatis Chatzimangou (st0pp3r), Huntrule TeamWindowssecurityHigh191Free2024-01-05Windows Process Creation: EDRSilencer Executed
Flags execution of EDRSilencer.exe on Windows based on process image and identifying metadata.
"@gott_cyber, Huntrule Team"Windowsprocess_creationHigh437Free2024-01-02Windows Process Execution of dotnet-trace.exe Child via '-- collect' Arguments
Alerts on dotnet-trace.exe executions with '-- ' and 'collect' command-line arguments that may proxy child process execution.
Jimmy Bayne (@bohops), Huntrule TeamWindowsprocess_creationMedium389Free2024-01-02macOS Process Execution of system_profiler for System Discovery via Specific Data Types
Flags macOS system_profiler runs that request application, hardware, network, and USB data via command-line data types.
Stephen Lincoln `@slincoln_aiq` (AttackIQ), Huntrule TeamMacosprocess_creationMedium444Free2024-01-02