Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Azure RiskDetection flags riskyIPAddress from anonymous proxy IP addresses
Alerts when Azure reports user activity linked to a risky anonymous proxy IP address.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh2410Free2023-09-03Azure Entra ID anomalous user activity risk event
Alerts on Azure AD risk events indicating anomalous user activity via riskEventType=anomalousUserActivity.
Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo', Huntrule TeamAzureriskdetectionHigh121Free2023-09-03Suspicious Child Process Spawned by WinRAR.exe on Windows
Alerts when WinRAR.exe launches command, scripting, or proxy execution binaries on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-08-31Qakbot Uninstaller Execution via QbotUninstall.exe (Windows Process Creation)
Alerts on execution of the QbotUninstall.exe uninstaller when it matches known Qakbot uninstaller hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-08-31Suspicious rundll32 Single-Digit DLL Execution with DllRegisterServer on Windows
Flags rundll32.exe running 1.dll with DllRegisterServer, a pattern seen in suspicious DLL execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2023-08-31Windows: WinRAR.exe Application Error Crash on Versions Below 6.23
Flags WinRAR.exe crash events on Windows when the installed version is below 6.23.x.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium111Free2023-08-31Windows: Detect WinRAR Creating .rev Files Associated with CVE-2023-40477
Alert on .rev file creation tied to WinRAR/Explorer on Windows as an indicator of potential CVE-2023-40477 exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow145Free2023-08-31Suspicious WinRAR Child Process Execution Attempt on Windows (CVE-2023-38331)
Alerts on WinRAR spawning command/scripting child processes tied to Temp\Rar$ activity consistent with CVE-2023-38331 exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationHigh162Free2023-08-30Windows: WinRAR double-extension file creation with space in Temp Rar$ path
Alerts on WinRAR-created Temp Rar$ files with double extensions separated by a space on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh357Free2023-08-30Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2023-08-29Windows: Local User Creation via net.exe with DarkGate and SafeMode
Alerts on net.exe adding a local user when the command line includes “DarkGate” and “SafeMode”.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2023-08-27Linux Process Discovery of Container Environment via ls -i on / Directory
Detects Linux commands that list inode information for '/' to probe whether execution is occurring inside a container.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow336Free2023-08-23Linux Docker Container Discovery via .dockerenv File Listing or Reads
Detects Linux process executions using common utilities to read or list .dockerenv, indicating potential container environment discovery.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow103Free2023-08-23Linux Container Discovery via /proc Virtual Filesystem Probing with CLI Text Tools
Flags Linux process executions using standard text tools to enumerate /proc for container-related discovery signals.
Seth Hanford, Huntrule TeamLinuxprocess_creationLow62Free2023-08-23Windows Fake wermgr.exe Execution via Renamed cmd/powershell/powershell_ise
Detects disguised execution of cmd or PowerShell by matching original file name with a wermgr.exe process image.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-08-23