Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows DNS Server CVE-2020-1350 RCE Indicators via Suspicious Child Process Creation
Alerts on non-benign subprocesses spawned by Windows DNS (dns.exe), consistent with CVE-2020-1350 exploitation attempts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical182Free2020-07-15Windows Process Creation: regsvr32 Invoked to Load .ocx from AppData Roaming
Flags regsvr32 /s /i loading an .ocx from AppData\Roaming on Windows, a stealthy code-loading technique.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical91Free2020-07-10Citrix ADC/ADS Exploitation Attempts Targeting RAPI and PCIDSS Paths (CVE-2020-8193/8195)
Flags Citrix ADC/NetScaler HTTP requests whose URI queries match exploitation-related patterns for CVE-2020-8193 and CVE-2020-8195.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical123Free2020-07-10Windows Registry Run Key Modification for ntkd Persistence
Flags Windows registry activity hitting the Run key path segment "\Run\ntkd" used for automatic startup persistence.
Aidan Bracher, Huntrule TeamWindowsregistry_eventCritical121Free2020-07-07Web Exploitation Attempt Pattern for CVE-2020-5902 on F5 BIG-IP (URI Traversal)
Alerts on web requests with query patterns consistent with CVE-2020-5902 exploitation attempts targeting F5 BIG-IP.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical92Free2020-07-05Windows Registry Markers for FlowCloud Malware Configuration and Keylogger Components
Detects registry activity referencing specific HARDWARE marker GUID keys and the Setup\PrintResponsor path on Windows.
NVISO, Huntrule TeamWindowsregistry_eventCritical63Free2020-06-09Confluence CVE-2019-3398 Web Exploitation via Path Traversal Upload POST Request
Alert on Confluence POST /upload.action requests with query-based path traversal filename patterns consistent with CVE-2019-3398.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical344Free2020-05-26Windows process command lines matching May 2020 Turla ComRAT command patterns
Triggers on Windows command lines matching a set of Turla-related indicators documented by ESET (May 2020).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical432Free2020-05-26Windows: Process executions matching Greenbug espionage tool indicators
Alerts on Windows process creation with command-line patterns matching PowerShell execution-policy bypass and reverse-shell related tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical3410Free2020-05-20Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical169Free2020-05-08Proxy Downloads Containing /pwndrop/ (PwnDrp Web Server)
Alerts on proxy requests to URIs containing '/pwndrop/', consistent with PwnDrp-style web delivery.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyCritical122Free2020-04-15Microsoft Exchange Web RCE Attempts via GET Requests Containing ECP/OWA and __VIEWSTATE
Alerts on web requests to Exchange ECP/OWA that include __VIEWSTATE= in the query.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical312Free2020-02-29Windows Process Creation: Sticky Keys Backdoor via sethc.exe Replacement
Flags forced replacement of C:\Windows\System32\sethc.exe with cmd.exe consistent with a Sticky Keys backdoor.
Sreeman, Huntrule TeamWindowsprocess_creationCritical116Free2020-02-18Windows: Dumpert Process Dumper Execution via Dumpert.dll or Known MD5
Detects Dumpert execution on Windows via known hash and command line reference to Dumpert.dll for lsass memory dumping.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical185Free2020-02-04Windows File Creation of Dumpert Default Dump (dumpert.dmp)
Alerts on creation of Dumpert’s default "dumpert.dmp" dump file on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical213Free2020-02-04