Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Execution of findstr.EXE for Security Tool Keyword Filtering
Alerts on Windows findstr.exe executions that filter output using security software and antivirus-related keywords.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium172Free2023-10-20Web exploitation attempts for CVE-2023-43261 causing info disclosure in Milesight routers
Alerts on successful GET requests for /lang/log/httpd.log in Milesight router web access logs, consistent with CVE-2023-43261 disclosure attempts.
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule Team—webserverHigh447Free2023-10-20Potential Information Disclosure via CVE-2023-43261 in Milesight Router Proxy Logs
Alerts on HTTP GET 200 responses for UR router log paths in proxy requests associated with CVE-2023-43261.
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule Team—proxyHigh153Free2023-10-20Cisco IOS XE Web UI Exploitation Indicators for CVE-2023-20198 via Syslog Login and Config Events
Matches Cisco IOS XE Web UI and web login success logs consistent with CVE-2023-20198 exploitation using specified admin/TAC usernames.
Lars B. P. Frydenskov (Trifork Security), Huntrule TeamCiscosyslogHigh2010Free2023-10-20Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsfile_eventHigh358Free2023-10-19Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
Nasreddine Bencherchali (Nextron Systems), Thurein Oo, Huntrule TeamWindowsregistry_setLow132Free2023-10-18Windows Process Execution: curl.exe Downloading Files From an IP URL
Flags curl.exe commands that download via an IP-based URL using output/remote-name flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium383Free2023-10-18Windows CertOC.exe Downloads File From IP-Based URL Using -GetCACAPS
Flags CertOC.exe executions using an IP-based URL in the command line with -GetCACAPS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2023-10-18Windows DLL Sideloading via ImageLoad of mscoRee/colorui/mapistub/HID payload DLLs
Alerts on Windows processes loading DLLs from targeted ProgramShared/ProgramData paths consistent with DLL sideloading.
Thurein Oo, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh161Free2023-10-18Windows rundll32.exe calling DllRegisterServer from a non-standard DLL path
Detects rundll32.exe calling DllRegisterServer from command lines associated with non-standard DLL locations.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationMedium70Free2023-10-17Windows regsvr32.exe Silent DLL execution invoking DllRegisterServer from uncommon paths
Alerts on regsvr32.exe /s /e executions of DLLs from potentially suspicious locations that may trigger DllRegisterServer.
Andreas Braathen (mnemonic.io), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-10-17DarkGate-related Autoit3.exe execution with suspicious parent process (Windows)
Alerts on AutoIt3.exe execution when spawned from cmd.exe, KeyScramblerLogon.exe, or msiexec.exe, excluding common legitimate install paths.
Micah Babinski, Huntrule TeamWindowsprocess_creationHigh143Free2023-10-15Windows Autoit3.exe Created by Uncommon Process (curl.exe/KeyScramblerLogon.exe/etc.)
Alerts on Windows events where Autoit3.exe is created, with the producing process matching curl.exe or other uncommon executables.
Micah Babinski, Huntrule TeamWindowsfile_eventMedium112Free2023-10-15Windows Process Creation: CoercedPotato.exe Execution via ExploitId Parameters
Flags Windows process creation for CoercedPotato.exe with --exploitId and known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh253Free2023-10-11Windows Named Pipe Creation with "\coerced\" PipeName Segment
Detects Windows named pipe creations where the pipe name contains the '\coerced\' pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdHigh122Free2023-10-11