Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows Process Creation: Serv-U CVE-2021-35211 Exploitation Command Pattern
Alerts on Windows process commands that combine 'whoami' with Serv-U-specific execution path and temp batch patterns tied to CVE-2021-35211.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical231Free2021-07-14Windows Registry: Flag Print Driver Registry Paths for QMS 810 and mimikatz
Detects registry TargetObject entries containing QMS 810 or mimikatz-related printer driver names under Windows print environments.
Markus Neis, @markus_neis, Florian Roth, Huntrule TeamWindowsregistry_eventCritical209Free2021-07-04Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)
Flags Windows Print Spooler Event ID 316 entries containing UNIDRV/mimispool-related keywords indicative of CVE-2021-1675 exploitation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprintservice-operationalCritical142Free2021-07-01Antivirus detections of PrinterNightmare PoC file creation path on Windows
Alerts on antivirus events where filenames include the Windows spooler driver x64 directory path, excluding Symantec submission messages.
Sittikorn S, Nuttakorn T, Tim Shelton, Huntrule Team—antivirusCritical469Free2021-07-01Windows File Events: PoC Filename Pattern for CVE-2021-1675 Spooler Exploitation
Flags Windows file events referencing a specific spooler driver path pattern associated with CVE-2021-1675 PoC activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical241Free2021-06-29Windows Execution of PurpleSharp HackTool by Image Name or Executable Metadata
Alerts on process creation events consistent with running PurpleSharp.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical191Free2021-06-18BabyShark HackTool Proxy C2 URL Pattern via momyshark?key=
Alerts on proxy URIs containing the BabyShark agent default "momyshark?key=" query pattern.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical123Free2021-06-09Windows Rundll32 Loads DLL Export StartNodeRelay (F-Secure C3)
Flags rundll32.exe launching a DLL that references the StartNodeRelay export in its command line.
Alfie Champion (ajpc500), Huntrule TeamWindowsprocess_creationCritical435Free2021-06-02Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowssystemCritical245Free2021-05-26Windows Named Pipe Creation Matching Cobalt Strike Default Pipe Prefixes
Flags Windows named pipe creation where PipeName matches known Cobalt Strike default pipe prefixes.
Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule TeamWindowspipe_createdCritical131Free2021-05-25Windows process creation patterns associated with DarkSide ransomware helpers
Detects Windows process creation consistent with DarkSide ransomware helper execution using encoded command-line content.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical163Free2021-05-14Webserver Indicators of Successful Exchange CVE-2021-28480 Exploitation via OWA Calendar POST
Flags POST requests to OWA calendar endpoint patterns linked to CVE-2021-28480, excluding HTTP 503 responses.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical162Free2021-05-14Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.
Bhabesh Raj, Huntrule TeamWindowssystemCritical3010Free2021-05-06Windows Driver File MoriyaStreamWatchmen.sys Created in System32\drivers
Alerts when the Windows system32 drivers directory receives the MoriyaStreamWatchmen.sys file.
Bhabesh Raj, Huntrule TeamWindowsfile_eventCritical141Free2021-05-06Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical192Free2021-03-09