Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
146 rules
Linux Process Creation: ESXi esxcli system discovery via system namespace
Alert on esxcli system invocations using get/list subcommands to discover ESXi system component information.
Cedric Maurugeon, Huntrule TeamLinuxprocess_creationMedium275Free2023-09-04Linux ESXi esxcli Storage Information Discovery via esxcli storage commands
Flags Linux process executions of esxcli with storage discovery subcommands like get/list.
Nasreddine Bencherchali (Nextron Systems), Cedric Maurugeon, Huntrule TeamLinuxprocess_creationMedium241Free2023-09-04Linux Process Execution of esxcli Network Commands for ESXi Network Discovery
Alerts when an ESXi esxcli command queries or lists network configuration via the "network" flag.
Cedric Maurugeon, Huntrule TeamLinuxprocess_creationMedium101Free2023-09-04Linux Process Discovery of Container Environment via ls -i on / Directory
Detects Linux commands that list inode information for '/' to probe whether execution is occurring inside a container.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow336Free2023-08-23Linux Docker Container Discovery via .dockerenv File Listing or Reads
Detects Linux process executions using common utilities to read or list .dockerenv, indicating potential container environment discovery.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow103Free2023-08-23Linux Container Discovery via /proc Virtual Filesystem Probing with CLI Text Tools
Flags Linux process executions using standard text tools to enumerate /proc for container-related discovery signals.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow82Free2023-08-23Windows: Detect Cmd.exe Redirection of Discovery Commands by Ursnif
Flags explorer-launched cmd.exe commands that use /C and redirect output to AppData local temp .bin files.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh356Free2023-07-16Linux grep file discovery targeting GobRAT-specific filenames
Alerts on grep executions on Linux whose arguments contain specific malware-related file names for discovery.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationHigh264Free2023-06-02Linux OS Architecture Discovery Using grep
Flags grep executions on Linux whose command line ends with known CPU/architecture identifiers.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationLow368Free2023-06-02Windows Devil Bait-like Recon via Wscript/Cmd with APPDATA Redirection
Flags cmd.exe launched by wscript.exe to redirect discovery output into %APPDATA%\Microsoft (.xml/.txt) using system enumeration commands.
Nasreddine Bencherchali (Nextron Systems), NCSC (Idea), Huntrule TeamWindowsprocess_creationHigh2210Free2023-05-15Windows Process Creation: Crassus Privilege Escalation Discovery Tool Execution
Identifies execution of the Crassus Windows privilege escalation discovery tool via process metadata.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh278Free2023-04-17Windows: Detect csvde.exe Active Directory export to CSV
Flags csvde.exe executions on Windows that include -f, consistent with exporting Active Directory data for discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium237Free2023-03-14Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Alerts on Windows executions referencing gatherNetworkInfo.vbs in process command lines, indicative of potential discovery activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh285Free2023-02-08Windows nltest.exe Execution for Network Information Discovery
Flags execution of nltest.exe (including nltestrk.exe via OriginalFileName) used for network and domain information discovery.
Arun Chauhan, Huntrule TeamWindowsprocess_creationLow130Free2023-02-03Windows WMIC System Information Discovery via WMIC.EXE Recon
Flags WMIC.EXE executions running system info queries for OS and disk details.
TropChaud, Huntrule TeamWindowsprocess_creationMedium262Free2023-01-26