Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical143Free2021-02-26Web server requests targeting WebLogic JNDI LDAP via JndiBindingHandle (CVE-2021-2109)
Alerts on GET requests with WebLogic JndiBindingHandle and an ldap:// payload targeting AdminServer.
Bhabesh Raj, Huntrule Team—webserverCritical409Free2021-01-20Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Flags Windows command lines where PowerShell/WMI is used to spawn rundll32 from c:\windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical173Free2021-01-20SolarWinds Orion Web API auth bypass probing via suspicious WebResource requests
Detects likely SolarWinds Orion API authentication bypass probing by matching suspicious WebResource/i18n endpoint query strings while filtering known valid requests.
Bhabesh Raj, Tim Shelton, Huntrule Team—webserverCritical182Free2020-12-27Windows rundll32.exe Command-Line RunDLL or Control_RunDLL Execution
Alerts on rundll32.exe process launches whose command lines end with RunDLL/Control_RunDLL, indicative of DLL function loading.
FPT.EagleEye, Huntrule TeamWindowsprocess_creationCritical201Free2020-12-25Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution
Alerts on Windows process executions with command-line substrings consistent with behaviors described in Lazarus activity reports.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowsprocess_creationCritical4110Free2020-12-23Detect SolarWinds SUPERNOVA Webshell URL Access on Webservers (logoimagehandler.ashx)
Identifies webserver traffic consistent with SUPERNOVA webshell access targeting logoimagehandler.ashx with a clazz query parameter.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical354Free2020-12-17Fortinet SSL VPN Exploitation Attempt via Path Traversal in Web Requests (CVE-2018-13379)
Alerts on HTTP requests matching a Fortinet SSL VPN traversal-style query indicative of CVE-2018-13379 exploitation.
Bhabesh Raj, Huntrule Team—webserverCritical141Free2020-12-08LockerGoga Ransomware Indicators in Windows Process Command Line
Flags Windows processes with a specific LockerGoga-style command-line argument pattern.
Vasiliy Burov, oscd.community, Huntrule TeamWindowsprocess_creationCritical192Free2020-10-18Windows Zerologon Exploitation Attempts via Mimikatz or Tools from Kali Host
Identifies Windows Zerologon exploitation attempts tied to Kali-hosted activity and mimikatz-related keywords.
Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community, Huntrule TeamWindowssystemCritical499Free2020-10-13Windows DCOM InternetExplorer.Application DLL Hijack via iertutil.dll Image Load
Alerts when iexplore.exe loads iertutil.dll from an Internet Explorer path, indicating possible DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, Huntrule TeamWindowsimage_loadCritical183Free2020-10-12Windows WMI DLL Hijack via Network-placed wbemcomn.dll in System32\wbem
Alerts when System creates wbemcomn.dll in C:\Windows\System32\wbem\, consistent with WMI DLL hijack file staging.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventCritical359Free2020-10-12Windows DCOM InternetExplorer.Application iertutil.dll DLL Hijack Suspicion
Alerts when System writes iertutil.dll in the DCOM InternetExplorer.Application path, consistent with potential DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, Huntrule TeamWindowsfile_eventCritical183Free2020-10-12Windows PowerShell: Detect Suspicious Opsec Artifacts in Script Module Content
Identifies PowerShell module content containing frequent offensive payload string markers associated with poor operational security.
ok @securonix invrep_de, oscd.community, Huntrule TeamWindowsps_moduleCritical445Free2020-10-09Windows Process Creation: Winnti Pipemon setup* Command-Line Parameters
Alerts on Windows processes launching Pipemon-style setup.exe command lines with specific -p or -x:n flags.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationCritical224Free2020-07-30