Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Suspicious DNS Queries to Operation Triangulation-Like Domains for C2 Beaconing
Detects DNS queries to known Operation Triangulation-related domains that may indicate C2 beaconing.
Florian Roth (Nextron Systems), Huntrule Team—dnsHigh91Free2023-06-01Windows: Detect w3wp.exe launching csc.exe for Dynamic Compilation (MOVEit CVE-2023-34362)
Flags IIS (w3wp.exe) spawning csc.exe within a MOVEit pool, consistent with dynamic compilation activity.
"@kostastsale, Huntrule Team"Windowsprocess_creationMedium447Free2023-06-01Windows File Activity Indicators of Potential MOVEit Transfer CVE-2023-34362 Exploitation
Finds MOVEit Transfer webroot file and ASP.NET compilation artifacts on Windows that may indicate CVE-2023-34362 exploitation.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh175Free2023-06-01Linux process-created writes to sensitive or critical files via shell redirection or editors
Alerts on Linux process command lines that redirect output or run editors while targeting sensitive/critical file paths.
"@d4ns4n_ (Wuerth-Phoenix), Huntrule Team"Linuxprocess_creationMedium171Free2023-05-30Webserver: Potential CVE-2023-25717 Ruckus Wireless Admin Injection via Unauthenticated HTTP GET
Alerts on suspicious GET requests to Ruckus Wireless Admin login endpoints containing '$(' payload markers.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh72Free2023-05-30Windows Scripting Engines Spawning regsvr32.exe via Parent Process Execution
Flags common script/command interpreters launching regsvr32.exe on Windows, a potential proxy execution behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium161Free2023-05-26Windows regsvr32 Execution from Suspicious DLL Paths
Alerts on regsvr32 runs whose command line references a DLL in highly suspicious Windows directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-05-26Windows regsvr32 Execution with DLL Path in Common Temporary/Public Directories
Alert on regsvr32.exe runs whose command line points to DLLs in Temp/Public-style directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium445Free2023-05-26Windows regsvr32 Execution of calc with /s flag
Alerts on regsvr32.exe runs using /s with a command line ending in calc.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh423Free2023-05-26Suspicious Windows regsvr32 Command-Line Uses FTP/HTTP to Register Remote Components
Alerts on regsvr32 command lines using /i flags with ftp/http content, consistent with remote DLL registration.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-05-24Windows DNS Server: Failed DNS Zone Transfer Requests (Event ID 6004)
Alerts on Windows DNS Server Event ID 6004 indicating a failed DNS zone transfer request for a non-existent or non-authoritative zone.
Zach Mathis, Huntrule TeamWindowsdns-serverMedium142Free2023-05-24Windows Rundll32 Execution via Suspicious DLL Path Without .dll Extension
Alerts when rundll32.exe is started from suspicious parent scripts with a DLL-like path missing the .dll extension.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical146Free2023-05-24Windows Qakbot-associated Rundll32 execution via suspicious parent process and export strings
Flags rundll32.exe executions tied to Qakbot-style export strings when launched by script/cmd utilities.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical81Free2023-05-24Windows rundll32.exe Execution via cmd/cscript/powershell with .dll and Suspicious Directories
Alerts on rundll32.exe execution with DLL arguments from common Windows script/LOLBins and suspicious staging paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-05-24Windows Registry: New ODBC Driver Registration in Suspicious Path
Alerts when Windows registers a new ODBC driver under the ODBCINST.INI area with details pointing to suspicious filesystem paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh266Free2023-05-23