Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows WMIC Remote Query Execution via /node
Identifies remote WMIC queries on Windows by matching WMIC execution with /node: in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-02-14Windows WMIC.exe Service Reconnaissance via Remote Service Queries
Flags WMIC.exe commands containing service-related reconnaissance strings while excluding stop/start service manipulation.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2023-02-14Windows WMIC.exe Product Class Reconnaissance via Security Product Queries
Detects wmic.exe being used to enumerate firewall, antivirus, and antispyware product classes.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium1910Free2023-02-14Windows WMIC Product Reconnaissance via Firewall/AV Enumeration
Alerts on wmic.exe executions with command lines consistent with Windows product enumeration for reconnaissance.
Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium154Free2023-02-14Windows wmic.exe Hardware Model Reconnaissance Using csproduct
Flags wmic.exe executions that include "csproduct" to query hardware model/vendor details.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium359Free2023-02-14Windows execution of LocalPotato POC (LocalPotato.exe with specific PE/CLI traits)
Detects LocalPotato.exe process execution on Windows using image path, typical CLI parameters, and known imphash values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2023-02-14Windows Suspicious Execution of Regasm/Regsvcs With Uncommon Command-Line Extension
Flags Regasm.exe/Regsvcs.exe runs that include unusual extensions in the command line, which may indicate stealthy misuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium221Free2023-02-13Windows: Filter Driver Unload via fltMC.exe
Flags fltMC.exe executions that include "unload" to indicate potential filter driver unloading for defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2023-02-13Potential CVE-2022-21587 Arbitrary File Upload Attempts via Oracle EBS Web Services
Alerts on POST requests with uueupload=TRUE targeting specific Oracle EBS OA_HTML services associated with CVE-2022-21587.
Isa Almannaei, Huntrule Team—webserverHigh133Free2023-02-13Velocity Application Errors Indicating Potential Server-Side Template Injection
Detects Velocity template rendering exceptions in application error logs that may indicate user-influenced SSTI attempts.
Moti Harmats, Huntrule TeamVelocityapplicationHigh102Free2023-02-11Potential SpEL Injection Attempts Triggering Spring ExpressionException (Application Logs)
Alerts on Spring ExpressionException errors that may indicate potential SpEL injection attempts.
Moti Harmats, Huntrule TeamSpringapplicationHigh453Free2023-02-11Node.js Application Errors Involving child_process Indicative of RCE Attempts
Flags Node.js ERROR logs mentioning node:child_process, which may signal command execution and possible RCE risk.
Moti Harmats, Huntrule TeamNodejsapplicationHigh91Free2023-02-11JVM Application Logs Indicating Potential XXE via XML Parser Exceptions
Alerts on JVM XML parsing exception messages in application error logs that may indicate attempted XXE exploitation.
Moti Harmats, Huntrule TeamJvmapplicationHigh114Free2023-02-11JVM Process Execution Exceptions in Application Logs
Flags JVM error logs showing failed process execution (ProcessBuilder/ProcessImpl) that may reflect attempted command execution.
Moti Harmats, Huntrule TeamJvmapplicationHigh219Free2023-02-11Potential OGNL Expression Injection Exploitation in JVM Application Logs
Detects ERROR-level JVM application log entries containing OGNL parsing/syntax exception indicators that may suggest OGNL injection attempts.
Moti Harmats, Huntrule TeamJvmapplicationHigh92Free2023-02-11