Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Security: Member Added to Security-Enabled Global Group
Alerts when Windows logs show a user was added to a security-enabled global group via Event ID 4728 or 632.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow334Free2023-04-26Windows Process Creation Indicators for PowerShell MSI Download and Silent Install (PaperCut MF/NG)
Detects hidden PowerShell downloading a setup.msi and silent msiexec installation tied to PaperCut MF/NG exploitation indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh231Free2023-04-25Suspicious Windows Network Connections to External IP Lookup Service APIs
Alerts on non-browser outbound connections from Windows hosts to public IP lookup API domains.
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium456Free2023-04-24Linux Process Creating xterm Reverse Shell Display Tunneling
Alerts on xterm processes started with -display and display endpoint ":1" consistent with a reverse shell tunnel.
"@d4ns4n_, Huntrule Team"Linuxprocess_creationMedium2710Free2023-04-24Linux Python Reverse Shell via pty and socket Module Execution
Alerts on Linux executions of Python -c commands that use socket and pty to connect and spawn a potential reverse shell.
"@d4ns4n_, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Linuxprocess_creationHigh258Free2023-04-24Windows PowerShell Invoke-WebRequest Execution via Direct IP in Command Line
Alerts when PowerShell executes web-request aliases targeting direct IP URLs, indicating possible remote content access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-04-21Windows Application: MSMQ Corrupted Packet (Event ID 2027, Level 2)
Alerts on MSMQ Event ID 2027 (level 2) indicating corrupted packets received by the service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh162Free2023-04-21Windows Scheduled Task Creation with Schtasks -XML Using Non-.xml File
Alerts when schtasks.exe creates a scheduled task using -XML but the referenced file does not end with .xml.
Swachchhanda Shrawan Poudel, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium292Free2023-04-20Windows: Suspicious child processes spawned by pc-app.exe (PaperCut MF/NG potential exploitation)
Alert on pc-app.exe spawning common command or scripting utilities on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntress DE&TH Team (idea), Huntrule TeamWindowsprocess_creationHigh156Free2023-04-20Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical150Free2023-04-20Windows Log4j/Wstomcat-related Process Execution via ws_tomcatservice.exe Parent
Detects processes spawned by ws_tomcatservice.exe on Windows, excluding repadmin.exe, to surface potential Tomcat exploitation.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationHigh393Free2023-04-20Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling
Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationCritical110Free2023-04-20Windows RDP client Mstsc.EXE launched from uncommon browser or email parent process
Alerts when mstsc.exe is spawned by a browser or Outlook, suggesting potential RDP access using a local .rdp file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2023-04-18Windows mstsc.exe launched with a local .rdp file from suspicious paths
Alerts on mstsc.exe executions that use a local .rdp file referenced from suspicious command-line paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-04-18Windows mstsc.exe launched with local .rdp file argument
Alerts on mstsc.exe executions that reference local .rdp files via the command line.
Nasreddine Bencherchali (Nextron Systems), Christopher Peacock @securepeacock, Huntrule TeamWindowsprocess_creationLow332Free2023-04-18