Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux Process Execution via Vim/Vi/Rvim/Vimdiff Shell and Script Escapes
Detects suspicious Vim/vi/vimdiff/rvim invocations that include Ex commands to run shell/proxy actions.
Nasreddine Bencherchali (Nextron Systems), Luc Génaux, Huntrule TeamLinuxprocess_creationHigh386Free2022-12-28Linux find Command Used to Discover SUID/SGID and World-Writable Files
Alerts on Linux usage of /find with setuid/sgid and permissive permission filters, consistent with discovery activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium519Free2022-12-28Linux Privilege Capability Discovery via getcap
Flags Linux executions of /getcap with -r to recursively enumerate file capabilities during discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow162Free2022-12-28Linux process execution via apt/apt-get Pre-Invoke shell command
Detects apt/apt-get executions using APT::Update::Pre-Invoke to trigger shell-like command execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium121Free2022-12-28Windows RDP Session Hijacking via tscon.exe from System Integrity
Flags tscon.exe executions on Windows running at System integrity, indicating potential RDP session hijacking.
"@juju4, Huntrule Team"Windowsprocess_creationMedium155Free2022-12-27Windows PowerShell Token Obfuscation via Process Command Line
Identifies Windows PowerShell command lines using token obfuscation patterns, common in Invoke-Obfuscation.
frack113, Huntrule TeamWindowsprocess_creationHigh2110Free2022-12-27SharpImpersonation Tool Execution on Windows
Flags execution of SharpImpersonation.exe on Windows when command-line parameters indicate token impersonation activity.
Sai Prashanth Pulisetti @pulisettis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-12-27Windows: Execution of Htran/NATBypass HackTool Binaries or Tran/Slave CLI Flags
Detects Windows executions of htran.exe or lcx.exe and command lines containing -tran or -slave flags.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-12-27Database SQL keyword matching suspicious queries (DROP/TRUNCATE/DUMP/SELECT *)
Alerts on SQL queries containing DROP, TRUNCATE, DUMP, or SELECT * indicative of potentially malicious database activity.
"@juju4, Huntrule Team"—databaseMedium92Free2022-12-27Windows PowerShell script token obfuscation via backtick and dynamic expression patterns
Find PowerShell script blocks that show token obfuscation patterns resembling Invoke-Obfuscation behavior.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2022-12-27Potential CVE-2022-46169 Command Injection Probe Against Cacti Web Server
Alert on GET requests to Cacti polldata endpoints containing command-injection payload fragments tied to CVE-2022-46169.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh414Free2022-12-27Linux userdel Execution: User Account Deletion via userdel
Flags Linux process executions of userdel, indicating possible user account deletion and related cleanup.
Tuan Le (NCSGroup), Huntrule TeamLinuxprocess_creationMedium357Free2022-12-26Linux groupdel Executed to Delete a User Group
Alerts when the Linux groupdel command is executed, indicating group deletion activity.
Tuan Le (NCSGroup), Huntrule TeamLinuxprocess_creationMedium162Free2022-12-26Windows PowerShell Inline Execution via File Reads and Raw Parameters
Alerts on PowerShell command lines that inline-execute content read from files using -raw.
frack113, Huntrule TeamWindowsprocess_creationMedium181Free2022-12-25Windows Process Creation: PowerShell COM CLSID Download Cradles
Alerts on PowerShell command lines using GetTypeFromCLSID with selected CLSIDs that may be used to download files via COM.
frack113, Huntrule TeamWindowsprocess_creationMedium214Free2022-12-25