Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)
Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical409Free2022-05-12Windows Hacktool Execution Flagged by Imphash in Process Creation
Alerts on Windows process executions where the import hash matches known hacktool binaries, even if renamed.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical486Free2022-03-04Windows Process Creation: DumpStack.log Used to Evade Microsoft Defender
Alerts on Windows processes launched with DumpStack.log in the image name and command-line output argument.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical112Free2022-01-06Grafana Web Path Traversal Exploitation (CVE-2021-43798) With 200 Responses
Alerts on Grafana web requests with traversal patterns in the URI query that return HTTP 200.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical3810Free2021-12-08Windows PowerShell Process Creation with DInjector Cradle Flags (/am51 and /password)
Identifies Dinject PowerShell cradle usage by matching command-line flags '/am51' and '/password' in Windows process creation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical4710Free2021-12-07Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
Florian Roth (Nextron Systems), Samir Bousseaden, Huntrule TeamWindowsprocess_creationCritical382Free2021-11-27Windows Process Creation: cmd.exe Spawned from Edge Elevation Service (CVE-2021-41379)
Alerts when cmd.exe or PowerShell spawns under Edge elevation service with SYSTEM integrity, consistent with CVE-2021-41379 exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical183Free2021-11-22Windows MSI Exec Creates elevation_service.exe Under Edge Path (CVE-2021-41379)
Flags msiexec creating elevation_service.exe within the Microsoft Edge application directory, indicating potential LPE exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical82Free2021-11-22Suspicious DNS Query Patterns for Cobalt Strike Beacons on Windows (Sysmon)
Alerts on Windows Sysmon DNS queries with QueryName patterns consistent with Cobalt Strike DNS beaconing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryCritical173Free2021-11-09Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Alerts on Windows file creation events for Mimikatz-related .kirbi and mimilsa.log files.
Florian Roth (Nextron Systems), David ANDRE, Huntrule TeamWindowsfile_eventCritical101Free2021-11-08Linux Network Connection to /bin/bash via Reverse Shell Pattern
Alerts on /bin/bash network connections to non-local destination IPs, consistent with reverse shell behavior.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionCritical131Free2021-10-16Linux auditd: Detect processes using --cpu-priority command-line parameter (possible miner behavior)
Alerts on Linux processes whose command line includes --cpu-priority, a common miner CPU tuning flag.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdCritical151Free2021-10-09Windows DLL Hijacking via Forced Load of C:\Windows\ADFS\version.dll
Alert on loading C:\Windows\ADFS\version.dll, a DLL hijacking indicator consistent with the FoggyWeb technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadCritical463Free2021-09-27Zoho ManageEngine ADSelfService Plus CVE-2021-40539 REST API exploit URL access (Web)
Flags web requests targeting ADSelfService Plus REST API paths linked to CVE-2021-40539 authentication bypass.
Sittikorn S, Nuttakorn Tungpoonsup, Huntrule Team—webserverCritical110Free2021-09-10Microsoft Exchange ProxyToken Exploitation via ECP POST and InboxRules NewObject (CVE-2021-33766)
Flags POSTs to Exchange ECP InboxRules endpoints with SecurityToken= that return HTTP 500, indicating ProxyToken exploitation attempts.
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule Team—webserverCritical151Free2021-08-30