Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Potential CVE-2021-26084 Confluence OGNL RCE Exploitation Attempt via POST
Flags successful POST requests consistent with OGNL injection attempts targeting Confluence page variable endpoints tied to CVE-2021-26084.
Sittikorn S, Nuttakorn T, Huntrule Team—webserverHigh81Free2022-12-13Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.
frack113, Huntrule TeamWindowsregistry_setHigh133Free2022-12-11Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Identifies uncommon setres.exe children matching '\choice' while excluding System32/SysWOW64 choice.exe.
"@gott_cyber, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh172Free2022-12-11Windows: Detect rcedit editing PE version/resource metadata via --set-*
Alerts on rcedit command-line usage that sets PE metadata fields to alter executable file properties.
Micah Babinski, Huntrule TeamWindowsprocess_creationMedium113Free2022-12-11Windows Privilege Escalation via mklink Symlink Between cmd.exe and osk.exe
Alerts on mklink creating a symlink between osk.exe and cmd.exe, enabling potential login-screen privilege escalation.
frack113, Huntrule TeamWindowsprocess_creationHigh4410Free2022-12-11Apache Solr CVE-2021-27905 Exploitation Attempt via Web Requests
Alerts when webserver logs show GET requests to Solr endpoints containing CVE-2021-27905-style debug/dump or fetchindex parameters with HTTP 200.
"@gott_cyber, Huntrule Team"—webserverMedium91Free2022-12-11Windows PowerShell nslookup DNS TXT Download Cradle
Identifies PowerShell launching an nslookup-based cradle that queries TXT records with HTTP-related nslookup parameters.
Sai Prashanth Pulisetti @pulisettis, Aishwarya Singam, Huntrule TeamWindowsps_classic_startMedium357Free2022-12-10Windows ETW Logging Disabled via SCM Registry TracingDisabled Key
Detects SCM ETW logging being disabled by setting the TracingDisabled registry DWORD for services.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow152Free2022-12-09Windows Registry Change Disables ETW for rpcrt4.dll via ExtErrorInformation
Flags Windows registry updates that disable ETW logging for rpcrt4.dll through ExtErrorInformation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow325Free2022-12-09Windows Process Creation: conhost.exe with High IntegrityLevel and -ForceV1
Flags conhost.exe started with -ForceV1 from a High integrity process on Windows.
frack113, Huntrule TeamWindowsprocess_creationInformational143Free2022-12-09Windows Image Load of Specific System DLLs Not Normally Present in System Directories
Alerts on image load events for specific system-path DLLs with unexpected “phantom” DLL names on Windows.
Nasreddine Bencherchali (Nextron Systems), SBousseaden, Huntrule TeamWindowsimage_loadHigh131Free2022-12-09Windows Registry: LSASS Full Dump via WER LocalDumps DumpType=2
Flags registry changes enabling LSASS full memory dumps by setting WER LocalDumps DumpType to 0x2.
"@pbssubhash, Huntrule Team"Windowsregistry_setHigh252Free2022-12-08Windows: LSASS Dump (.dmp) Files in CrashDumps Folder
Alerts when an lsass.exe dump (.dmp) appears in the Windows CrashDumps directory under systemprofile.
"@pbssubhash, Huntrule Team"Windowsfile_eventHigh399Free2022-12-08Windows Application Error: LSASS (lsass.exe) Crashed (Event ID 1000)
Alerts on Application Error (Event ID 1000) entries where lsass.exe crashes, using Windows Application event telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh2010Free2022-12-07Windows windefend alerts on suspicious Windows Defender configuration changes (Disable* and SpyNet reporting)
Alerts on windefend Event 5007 when Defender configuration changes set features like anti-spyware, scanning, or SpyNet reporting to disabled values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowswindefendHigh286Free2022-12-06