Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
GitHub Audit: Outside Collaborator Membership and Permission Changes
Alerts on GitHub audit events involving outside collaborators being removed or permission changes on projects.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditMedium103Free2023-01-20GitHub audit: New Actions secret created for org, environment, repo, or Codespaces
Triggers on GitHub audit events when an actor creates a new Actions secret for org, environment, Codespaces, or repo.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditLow229Free2023-01-20Detect CentOS Web Panel POST login reverse-shell RCE attempts (CVE-2022-44877)
Alert on POST requests to CentOS Web Panel login that contain command-execution and reverse-shell style query parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh221Free2023-01-20Windows driverquery.exe Process Execution Detection
Alerts on Windows executions of driverquery.exe (drvqry.exe) used to enumerate installed drivers, with parent-process exclusions to reduce duplicates.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2023-01-19Windows: driverquery.exe Usage for Installed Driver Recon
Alerts when driverquery.exe (drvqry.exe) is launched by script-based parent processes to enumerate installed drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2023-01-19Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
Flags successful Windows SMB (LogonType 3) logons from non-private, non-local source IP addresses.
Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity), Huntrule TeamWindowssecurityHigh60Free2023-01-19Windows RDP Successful Logon (4624 LogonType 10) from Public IP
Alerts on successful RDP (LogonType 10) from a non-private, non-local source IP in Windows Security Event 4624.
Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity), Huntrule TeamWindowssecurityMedium70Free2023-01-19Okta Admin Role Assignment Created via iam.resourceset.bindings.add
Detects creation of new admin role assignments in Okta when an IAM resource set binding is added.
Nikita Khalimonenkov, Huntrule TeamOktaoktaMedium371Free2023-01-19GitHub Audit Log: Delete Actions for Codespaces, Environments, Projects, and Repositories
Alerts on GitHub audit log deletion actions for Codespaces, environments, projects, and repositories.
Muhammad Faisal (@faisalusuf), Huntrule TeamGithubauditMedium4010Free2023-01-19Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2023-01-18Linux iptables/ufw Firewall Rule Flush via Process Execution
Flags Linux iptables/ufw activity that flushes firewall rules and can allow broad network traffic.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationMedium387Free2023-01-18Linux UFW Disable Attempt via Process Execution
Flags Linux commands that stop/flush/unload or disable UFW, reducing firewall protection and exposure.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationMedium248Free2023-01-18Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Alerts on Windows Defender Firewall configurations where all rules are deleted (Event 2033/2059), signaling potential defense impairment.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asHigh163Free2023-01-17PowerShell Data Exfiltration Using Audio File (WAV BinaryWriter) on Windows
Alerts on PowerShell script blocks that appear to write data into an audio (WAV) file for potential exfiltration.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium142Free2023-01-16Windows DNS Client: DNS queries containing "ufile.io"
Alerts on Windows DNS Client queries where the queried name includes "ufile.io".
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientLow173Free2023-01-16