Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Masquerading as svchost.exe via Binary Name and Location
Alerts on svchost.exe-named processes launched from non-standard paths with OriginalFileName svchost.exe.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh501Free2024-08-07Windows File Access to Cryptocurrency Wallet Keystores by Uncommon Processes
Alerts on access to Ethereum/Bitcoin-style wallet files from non-standard processes on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessMedium379Free2024-07-29Windows Process Creation Ending in .exe With No Image Name
Flags Windows process creation events where the .exe path exists but the image name is missing, indicating possible stealth or evasion.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium163Free2024-07-23Windows: Detect execution of renamed BOINC.exe binary
Flags renamed BOINC executables on Windows by matching OriginalFileName=BOINC.exe when the executed image name differs.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium518Free2024-07-23PowerShell Launch With --headless From Conhost.exe on Windows
Flags headless ConHost launching PowerShell on Windows based on process name and command-line arguments.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium152Free2024-07-23Windows: Uncommon Process Access to Microsoft Teams Cookies or Local Storage leveldb
Alerts on access to Teams Cookies or leveldb files by processes other than Teams.exe on Windows.
"@SerkinValery, Huntrule Team"Windowsfile_accessMedium141Free2024-07-22Windows COM CLSID Hijacking via Registry Default InprocServer32/LocalServer32 Modification
Detects registry changes to COM CLSID Default InprocServer32/LocalServer32 values that point to suspicious locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh403Free2024-07-16Windows Process Creation: Renamed Microsoft Teams Executable Launch
Alerts when Microsoft Teams binaries are launched under renamed executable names on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium261Free2024-07-12Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Alerts when DsrmAdminLogonBehavior registry value is changed on Windows, except the default DWORD 0x00000000.
Nischal Khadgi, Huntrule TeamWindowsregistry_setHigh452Free2024-07-11Windows Process Execution of BitLockerToGo.EXE
Alerts on Windows execution of BitLockerToGo.exe, a rarely used BitLocker To Go component for portable drive encryption.
Josh Nickels, mttaggart, Huntrule TeamWindowsprocess_creationLow4010Free2024-07-11Windows DLL Sideloading Suspected for ms<wbr>corsvc.dll via ImageLoad
Alerts on non-standard loads of msocrsvc.dll, a potential DLL sideloading opportunity on Windows.
Wietze Beukema, Huntrule TeamWindowsimage_loadMedium163Free2024-07-11Windows DLL Sideloading via MpSvc.dll Image Load Anomaly
Flags Windows module loads of MpSvc.dll outside typical Defender/WinSxS locations that may indicate DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema, Huntrule TeamWindowsimage_loadMedium317Free2024-07-11Potential DLL Sideloading: Image Load of DbgModel.dll on Windows
Alerts when a process loads DbgModel.dll from a non-standard path, suggesting possible DLL sideloading.
Gary Lobermier, Huntrule TeamWindowsimage_loadMedium439Free2024-07-11Windows: Detect regedit.exe creating a PDF file
Alerts when RegEdit.exe creates a .pdf file on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh306Free2024-07-08Windows Registry: DisableHypervisorEnforcedPagingTranslation Set to 1
Alerts when Windows disables Hypervisor Enforced Paging Translation by setting DisableHypervisorEnforcedPagingTranslation to 1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2024-07-05