Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Webserver: OWASSRF exploitation attempt via OWA to PowerShell backend
Flags webserver POSTs returning 200 that request both /owa/mastermailbox and /powershell, consistent with OWASSRF exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverCritical172Free2022-12-22Detect OWASSRF Webserver Exploitation Pattern Targeting PowerShell Backend
Alerts on successful POST requests to OWA URLs containing PowerShell backend indicators and Exchange-like probe user agents.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh111Free2022-12-22Detects OWASSRF Proxy Exploitation Attempt via OWA to PowerShell Backend
Identifies proxy POSTs that return 200 and request both /owa/mastermailbox and /powershell, indicating potential OWASSRF exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyCritical162Free2022-12-22Potential OWASSRF Exploitation via OWA Proxy Requests (HTTP 200) - Exchange
Alerts on 200-status proxy POSTs targeting OWA-to-PowerShell backend paths with encoded user info markers.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh161Free2022-12-22Windows Process Creation: Impersonate.exe HackTool Execution
Flags execution of impersonate.exe (Impersonate tool) on Windows using command-line subcommands or known hashes.
Sai Prashanth Pulisetti @pulisettis, Huntrule TeamWindowsprocess_creationMedium81Free2022-12-21Linux: usermod used to add users to root or sudoers groups
Detects usermod commands that append a user to root or sudoers groups, indicating potential privilege escalation persistence.
TuanLe (GTSC), Huntrule TeamLinuxprocess_creationMedium395Free2022-12-21Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access
Alerts on Linux user creation events that assign privileged UID/GID values like root, wheel, or sudo.
Pawel Mazur, Huntrule TeamLinux—High103Free2022-12-21Windows Registry Set Detection of Suspicious Environment Variable Commands
Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh297Free2022-12-20Windows Office Binary Execution with Renamed Image Path
Alerts when Office apps are executed under renamed or unexpected image paths, helping catch stealthy masquerading on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-12-20Windows SQLite CLI Querying Chromium Browser Profile Databases
Alerts when SQLite CLI is used to query Chromium-based browser profile databases containing logins, cookies, or history.
TropChaud, Huntrule TeamWindowsprocess_creationHigh198Free2022-12-19Windows DLL Sideloading via comctl32.dll in .local directories
Alerts on comctl32.dll loaded from System32 .local folders, consistent with Windows DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Subhash Popuri (@pbssubhash), Huntrule TeamWindowsimage_loadHigh4310Free2022-12-16Windows File Events: Suspicious .exe.local Path With comctl32.dll in System32
Detects System32 *.exe.local entries that reference comctl32.dll, consistent with DLL sideloading behavior.
Nasreddine Bencherchali (Nextron Systems), Subhash P (@pbssubhash), Huntrule TeamWindowsfile_eventHigh161Free2022-12-16Windows DLL Sideloading Indicator: JsSchHlp Loads JSESPR.dll from Untrusted Path
Alerts on unexpected loads of \JSESPR.dll, indicating possible DLL sideloading outside the Justsystem JsSchHlp directory.
frack113, Huntrule TeamWindowsimage_loadMedium153Free2022-12-14Windows DLL Sideloading: ClassicExplorer32.dll Loaded from Unexpected Path
Alerts when ClassicExplorer32.dll is loaded from unexpected locations, suggesting possible DLL sideloading behavior.
frack113, Huntrule TeamWindowsimage_loadMedium102Free2022-12-13AWS SES Identity Deleted via CloudTrail DeleteIdentity Event
Flags CloudTrail events showing an SES identity was deleted using the DeleteIdentity API.
Janantha Marasinghe, Huntrule TeamAwscloudtrailMedium296Free2022-12-13