Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows Process Creation Matching TrustedPath UAC Bypass Directory Mocking Strings
Alerts on Windows processes referencing System32/SysWOW64 paths consistent with TrustedPath UAC bypass directory mocking.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical132Free2021-08-27MODX Manager Path Traversal Attempt via tvs.php class_key (CVE-2010-5278)
Alerts on HTTP requests to MODx tvs.php with traversal-based class_key payload indicative of LFI attempts.
Subhash Popuri (@pbssubhash), Huntrule Team—webserverCritical161Free2021-08-25Web Exploitation of Arcadyan Router Path Traversal and Config Injection Attempts
Detects Arcadyan router exploit traffic by matching URL-encoded path traversal patterns in query strings linked to config injection.
Bhabesh Raj, Huntrule Team—webserverCritical389Free2021-08-24Exchange Management: Certificate CSR exported to webserver or .aspx-named path
Flags Exchange CSR export commands that write request files to C$ and web-root paths or use an .aspx filename.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical152Free2021-08-23Fortinet WAF: Detect POST to /api/v2.0/user/remoteserver.saml (CVE-2021-22123 attempt)
Flags suspicious Fortinet WAF HTTP POST requests targeting a remoteserver.saml API query pattern consistent with CVE-2021-22123 exploitation.
Bhabesh Raj, Florian Roth, Huntrule Team—webserverCritical152Free2021-08-19Windows whoami.exe Renamed Execution via Mismatched OriginalFileName
Alerts when a renamed process still reports OriginalFileName as whoami.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical80Free2021-08-12Windows SystemNightmare Exploitation Attempt via PrintNightmare Command Lines
Alerts on Windows process command lines matching SystemNightmare/PrintNightmare exploitation indicators that may enable LOCAL_SYSTEM shell access.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical173Free2021-08-11Exchange ProxyLogon activity: IIS POST SetObject Reset VirtualDirectory requests
Alerts on successful POSTs to ECP DDIService SetObject resetting a VirtualDirectory with a '$' username suffix.
frack113, Huntrule Team—webserverCritical101Free2021-08-10Microsoft Exchange: Mailbox export to UNC path or .aspx filename with possible role assignment
Flags Exchange mailbox export commands targeting UNC paths with .aspx or granting the Mailbox Import Export role.
Florian Roth (Nextron Systems), Rich Warren, Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical284Free2021-08-09Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation
Flags Exchange management command lines invoking Set-OabVirtualDirectory with suspicious external URL/script injection patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical4010Free2021-08-09Successful ProxyShell-like Exchange exploitation via autodiscover.json and PowerShell/MAPI paths
Flags Exchange-targeted web requests with /autodiscover.json plus exploit URI fragments returning 200/301.
Florian Roth (Nextron Systems), Rich Warren, Huntrule Team—webserverCritical123Free2021-08-09Windows Named Pipe Creation Matching Cobalt Strike Malleable C2 Profile Patterns
Alerts on Windows named pipe creation with PipeName patterns consistent with Cobalt Strike Malleable C2 behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdCritical214Free2021-07-30Windows Hacktool Execution Indicators for SMB/NTLM Relay and Potato-Style Privilege Escalation
Alerts on Windows execution of common SMB/NTLM relay and “Potato” privilege escalation hacktool indicators via process creation fields.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical161Free2021-07-24Windows Registry Modification Indicative of CVE-2021-31979 and CVE-2021-33771 Exploitation
Flags registry changes to targeted COM InprocServer32 CLSID paths tied to CVE-2021-31979/33771 exploitation behavior on Windows.
Sittikorn S, frack113, Huntrule TeamWindowsregistry_setCritical338Free2021-07-16Windows file event detection for CVE-2021-31979 and CVE-2021-33771 exploitation artifact paths
Flags Windows file events where the target filename matches paths tied to CVE-2021-31979/CVE-2021-33771 exploitation patterns.
Sittikorn S, Huntrule TeamWindowsfile_eventCritical212Free2021-07-16