Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,750 rules
Java Spring Framework Exception Alerts for Access Denied and CSRF Failures
Alerts on Spring Security exception keywords related to access denial, CSRF, cookies, and request rejection in application logs.
Thomas Patzke, Huntrule TeamSpringapplicationMedium112Free2017-08-06Ruby on Rails Exception Keyword Alerts for Invalid Requests
Flags Rails ActionController exceptions in application logs that may signal probing or exploitation via invalid requests.
Thomas Patzke, Huntrule TeamRuby_on_railsapplicationMedium393Free2017-08-06Django Application Error Exceptions Matching SuspiciousOperation and Security Exceptions
Identifies Django logs containing suspicious security-related exception names that may indicate exploitation attempts.
Thomas Patzke, Huntrule TeamDjangoapplicationMedium256Free2017-08-05Windows Security: Account Encryption/Preauth/Delegation Flags Weakened in User Account Changes
Flags Windows Event ID 4738 user account changes that enable weaker encryption or related pre-auth behavior.
"@neu5ron, Huntrule Team"WindowssecurityHigh445Free2017-07-30Windows Security: SeEnableDelegationPrivilege Enabled via AD User Right (Event 4704)
Alerts when Event ID 4704 assigns SeEnableDelegationPrivilege, enabling control over other AD user objects.
"@neu5ron, Huntrule Team"WindowssecurityHigh401Free2017-07-30Windows rundll32 execution matching ZxShell function and remote disk strings
Alerts on rundll32.exe command lines containing zxFunction and RemoteDiskXXXXX indicative of ZxShell execution.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationCritical52Free2017-07-20Suspicious Malformed User-Agent Strings in Proxy Logs
Flags proxy requests whose User-Agent headers are malformed or match suspicious automation/tooling patterns, excluding known Adobe/Acrobat traffic.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh165Free2017-07-08Suspicious Malware User-Agent Strings in Proxy Logs
Alerts on proxy traffic with user-agent values and substrings commonly seen in malware communications.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebproxyHigh111Free2017-07-08Proxy logs: Detect suspicious hack tool user agents from known scanning and SQLi tools
Alerts on proxy requests with User-Agent values commonly used by scanners and hack tools, indicating automated probing or exploitation attempts.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh133Free2017-07-08Proxy logs: suspicious exploit framework User-Agent strings
High-severity match on proxy User-Agent strings commonly seen in exploit/pentest frameworks.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh172Free2017-07-08Proxy HTTP Requests with Empty User-Agent Header
Flags proxy HTTP traffic with an empty User-Agent header, which may indicate automation or unusual client behavior.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyMedium101Free2017-07-08Linux VSFTPD Logs: Suspicious Error Messages Indicating Possible Exploitation Attempts
Looks for specific vsftpd error strings that may indicate exploitation-triggered faults or abnormal request handling.
Florian Roth (Nextron Systems), Huntrule TeamLinuxvsftpdMedium156Free2017-07-05Linux SSHD Logs: Suspicious OpenSSH Daemon Error Keywords
Alerts on sshd log entries with specific OpenSSH fatal or cryptographic error messages indicating suspicious access attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsshdMedium113Free2017-06-30Windows Security Events Indicating File Deletion Attempts Using SDelete Extensions
Alerts on Windows security file access events for object names ending in .AAA or .ZZZ, consistent with secure deletion behavior.
Thomas Patzke, Huntrule TeamWindowssecurityMedium101Free2017-06-14Windows WCE wceaux.dll File Access via Security Event 4656/4663
Identifies Windows Security event activity involving access to the wceaux.dll library file.
Thomas Patzke, Huntrule TeamWindowssecurityCritical122Free2017-06-14