Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,067 rules
Linux JexBoss Suspicious Bash Command Launch with /dev/tcp
Flags Linux executions containing bash -c /bin/bash paired with /dev/tcp/ indicative of a reverse-shell command sequence.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High458Free2017-08-24sshd Buffer Underflow Error Message Matching CVE-2018-15473 Exploit Attempt (Linux)
Flags Linux sshd pre-auth buffer parsing error messages that align with CVE-2018-15473 exploit attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsshdMedium314Free2017-08-24Windows WMI Persistence via Event Filter/Consumer Bindings and Filter Registration
Flags likely WMI-based persistence by spotting event filter/consumer bindings and WMI filter registrations tied to script/command-line consumers.
Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule TeamWindowswmiMedium204Free2017-08-22Windows WMI Persistence via Security Event 4662 on WMI subscription namespace
Alerts on Security Event 4662 indicating access to WMI Namespace objects with "subscription" in the name.
Florian Roth (Nextron Systems), Gleb Sukhodolskiy, Timur Zinniatullin oscd.community, Huntrule TeamWindowssecurityMedium61Free2017-08-22Linux Suspicious Shell Command Lines for Exploit/Payload Delivery
Detects Linux command-line strings matching wget/piping, payload staging, permission changes, and socat/HTTP server execution patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High4010Free2017-08-21Windows svchost.exe Spawned by Uncommon Parent Process
Alerts when svchost.exe starts with an unusual parent process name on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium63Free2017-08-15Python SQL Exception Errors Indicating Database Interaction Failures
Identifies Python application logs referencing common SQL exception classes from DB-API (PEP 249).
Thomas Patzke, Huntrule TeamPythonapplicationMedium418Free2017-08-12Java Spring Framework Exception Alerts for Access Denied and CSRF Failures
Alerts on Spring Security exception keywords related to access denial, CSRF, cookies, and request rejection in application logs.
Thomas Patzke, Huntrule TeamSpringapplicationMedium92Free2017-08-06Ruby on Rails Exception Keyword Alerts for Invalid Requests
Flags Rails ActionController exceptions in application logs that may signal probing or exploitation via invalid requests.
Thomas Patzke, Huntrule TeamRuby_on_railsapplicationMedium333Free2017-08-06Django Application Error Exceptions Matching SuspiciousOperation and Security Exceptions
Identifies Django logs containing suspicious security-related exception names that may indicate exploitation attempts.
Thomas Patzke, Huntrule TeamDjangoapplicationMedium176Free2017-08-05Windows Security: Account Encryption/Preauth/Delegation Flags Weakened in User Account Changes
Flags Windows Event ID 4738 user account changes that enable weaker encryption or related pre-auth behavior.
"@neu5ron, Huntrule Team"WindowssecurityHigh445Free2017-07-30Windows Security: SeEnableDelegationPrivilege Enabled via AD User Right (Event 4704)
Alerts when Event ID 4704 assigns SeEnableDelegationPrivilege, enabling control over other AD user objects.
"@neu5ron, Huntrule Team"WindowssecurityHigh401Free2017-07-30Windows rundll32 execution matching ZxShell function and remote disk strings
Alerts on rundll32.exe command lines containing zxFunction and RemoteDiskXXXXX indicative of ZxShell execution.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationCritical52Free2017-07-20Suspicious Malformed User-Agent Strings in Proxy Logs
Flags proxy requests whose User-Agent headers are malformed or match suspicious automation/tooling patterns, excluding known Adobe/Acrobat traffic.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh125Free2017-07-08Suspicious Malware User-Agent Strings in Proxy Logs
Alerts on proxy traffic with user-agent values and substrings commonly seen in malware communications.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebproxyHigh81Free2017-07-08