Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Network Connections to *.devtunnels.ms
Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium91Free2023-11-20Windows Process Creation: Detect Event Log Query via wmic.exe, wevtutil.exe, or PowerShell
Detects command-line attempts to query Windows Event Logs using wevtutil, wmic, or Get-WinEvent/Get-EventLog.
Ali Alwashali, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-11-20Webserver POST requests to Confluence setup/restore endpoints matching CVE-2023-22518 exploit traffic
Detects POST traffic to Confluence CVE-2023-22518 vulnerable endpoints based on URI patterns and HTTP status codes.
Andreas Braathen (mnemonic.io), Huntrule Team—webserverMedium122Free2023-11-14HTTP POST exploitation attempt against Confluence CVE-2023-22518 vulnerable setup endpoints (Proxy logs)
Flags proxy POST requests to known Confluence setup/admin endpoints returning 200/302/405, aligned with CVE-2023-22518 exploitation attempts.
Andreas Braathen (mnemonic.io), Huntrule Team—proxyMedium123Free2023-11-14Windows: Detects Suspicious cmd.exe or PowerShell spawned from Confluence (tomcat) Processes
Alerts when Confluence/embedded Tomcat spawns cmd.exe or PowerShell on Windows, indicating possible command execution after exploitation.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationMedium81Free2023-11-14CVE-2023-22518 Confluence Exploitation Attempt via Suspicious Bash/Curl/Wget Child Processes on Linux
Alerts when Confluence Java spawns shell/download tools on Linux consistent with CVE-2023-22518 exploitation behavior.
Andreas Braathen (mnemonic.io), Huntrule TeamLinuxprocess_creationHigh409Free2023-11-14Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
Alerts when excel.exe spawns foxprow.exe, schdplus.exe, or winproj.exe, consistent with suspicious Excel DCOM automation activity.
Aaron Stratton, Huntrule TeamWindowsprocess_creationHigh143Free2023-11-13Windows: Command-Line Use of ms-appinstaller Protocol Handler for File Downloads
Alerts on Windows command lines invoking ms-appinstaller with an http source, indicating potential remote file download behavior.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium242Free2023-11-09Windows msxsl.exe Execution with HTTP Keyword in Command Line
Flags execution of msxsl.exe when the command line includes an HTTP URL indicator.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh70Free2023-11-09Windows: File Download via msedge_proxy.exe Using HTTP/HTTPS URLs
Flags msedge_proxy.exe executions that include HTTP/HTTPS URLs, consistent with arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium168Free2023-11-09Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS
Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh373Free2023-11-09Windows: Detect SysAid user.exe Loader Execution by Filename and SHA256 Hash
Flags execution of a specific SysAid-hosted Windows binary when the process image path and SHA256 match.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2023-11-09Windows Process Execution for PowerShell Cobalt Strike Download via Hidden IEX
Flags PowerShell command lines that use IEX and hidden downloadstring to fetch a Cobalt Strike payload.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2023-11-09Windows PowerShell script launcher matching SysAidServer Tomcat paths
Flags PowerShell script block text tied to SysAid Tomcat webapp paths and user.exe staging/launch actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh113Free2023-11-09PowerShell Script Evidence Eraser Searching for cleanLL and usersfiles.war
Identifies PowerShell script blocks containing evidence-cleanup indicators and a repeating while(1) loop.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh407Free2023-11-09