Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows Process Execution Matches Griffon Malicious Command-Line Pattern
Alerts on Windows process command lines containing a temp staging path plus jscript execution indicators and a .txt target.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical172Free2023-03-09Windows DNS Client: Cobalt Strike DNS Beaconing Patterns via Suspicious Query Names
Alerts when Windows DNS client logs show Event ID 3008 DNS queries matching Cobalt Strike beacon patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientCritical4410Free2023-01-16Webserver: OWASSRF exploitation attempt via OWA to PowerShell backend
Flags webserver POSTs returning 200 that request both /owa/mastermailbox and /powershell, consistent with OWASSRF exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverCritical172Free2022-12-22Detects OWASSRF Proxy Exploitation Attempt via OWA to PowerShell Backend
Identifies proxy POSTs that return 200 and request both /owa/mastermailbox and /powershell, indicating potential OWASSRF exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyCritical162Free2022-12-22Windows Process Creation: SysmonEOP.exe HackTool Execution (CVE-2022-41120 PoC)
Alert on Windows process execution of \SysmonEOP.exe with specific IMPhashes associated with the SysmonEOP PoC.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical208Free2022-12-04Inveigh Execution via Process Creation (Windows)
Detects execution of Inveigh.exe on Windows with spoofing/sniffing command-line flags consistent with MITM behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical305Free2022-10-24Windows Inveigh HackTool Execution Artefacts via Inveigh File Indicators
Alert on Windows file creation or presence of Inveigh log, script, and binary artefacts identified by distinctive filename suffixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical427Free2022-10-24Windows Process Execution: SafetyKatz HackTool (SafetyKatz.exe)
Alerts when a process running SafetyKatz.exe is created, using image path and embedded file metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2022-10-20Windows Security: Suspicious SAMTHEADMIN-* Computer/Account Names Ending with $
Alerts on Windows Security events with computer account names starting SAMTHEADMIN- and ending with $.
elhoim, Huntrule TeamWindowssecurityCritical171Free2022-09-09Windows process command line matching Sliver C2 implant NoExit PowerShell UTF8 pattern
Alerts on Windows process command lines matching a Sliver-style PowerShell -NoExit encoding pattern.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical152Free2022-08-25Windows: SharpUp (SharpUp.exe) Local Privilege Escalation Tool Execution
Flags SharpUp.exe execution on Windows when command line indicators reference common privilege-escalation targets.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical203Free2022-08-20Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical407Free2022-08-03Windows Security: DiagTrackEoP POC Default UserName Login Attempt (LogonType 9)
Alerts on Windows 4624 LogonType 9 events targeting a known DiagTrackEoP default username.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityCritical120Free2022-08-03Windows: Detect Named Pipe Creation with Koh Default Names
Alerts on Windows named pipe creation with Koh default identifiers in the pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical421Free2022-07-08Windows File Events: wmiexec Default Output File Creation (__1<9 digits>.<1-7 digits>)
Detects Windows file creation matching wmiexec default output filename patterns in admin share and drive paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical287Free2022-06-02