Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry: EnablePeriodicBackup value set for periodic system hive backups
Alerts on enabling the Windows registry setting that triggers periodic system hive backups to RegBack on restarts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium132Free2024-07-01Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Flags and image indicators for RemoteKrbRelay execution on Windows, including relaying-related command-line actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh417Free2024-06-27Windows File Drop Indicators for RemoteKrbRelay SMB Relay Secret Dump Module
Alerts on creation of RemoteKrbRelay-specific temp files used to stage secrets dump outputs on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh354Free2024-06-27Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule TeamWindowsprocess_creationHigh231Free2024-06-26SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2024-06-26Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh191Free2024-06-26Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.
Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh258Free2024-06-26Windows Process Execution: LaZagne Credential Dumping Utility (lazagne.exe)
Flags Windows process launches consistent with running LaZagne (lazagne.exe) for credential and password recovery.
Nasreddine Bencherchali, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2024-06-24Windows Network Connections to azurewebsites.net from Non-Browser Processes
Alerts on outbound connections to azurewebsites.net started by non-browser processes on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium202Free2024-06-24Windows File Creation: System DLL Named .dll in Uncommon Locations
Alerts on creation of .dll files named like system DLLs in unexpected Windows directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium163Free2024-06-24Windows DNS Queries to azurewebsites.net From Non-Browser Processes
Alerts on DNS queries to azurewebsites.net from processes other than common browsers, using Windows DNS query and process image telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryMedium237Free2024-06-24Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Alerts on initiated outbound connections from Windows hosts to LocaltoNet/.localtonet.com tunneling domains.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsnetwork_connectionHigh173Free2024-06-17Windows: Suspicious Qemu execution with low-memory and network-tunneling flags
Alerts on Windows Qemu command lines using low -m values plus -netdev/connect= and -nographic.
Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR), Huntrule TeamWindowsprocess_creationMedium192Free2024-06-03Windows Recall Enabled by Registry: DisableAIDataAnalysis Set to 0 (Windows)
Alerts when Windows Recall is enabled by setting the DisableAIDataAnalysis policy value to 0.
Sajid Nawaz Khan, Huntrule TeamWindowsregistry_setMedium151Free2024-06-02Windows Recall Enabled by Deleting DisableAIDataAnalysis Registry Value
Flags deletion of WindowsAI\DisableAIDataAnalysis policy value indicating Windows Recall may be enabled.
Sajid Nawaz Khan, Huntrule TeamWindowsregistry_deleteMedium4410Free2024-06-02