Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,460 rules
Windows DNS Client detects queries to Put.io subdomains (api.put.io, upload.put.io)
Alert on Windows DNS Client queries containing api.put.io or upload.put.io.
Omar Khaled (@beacon_exe), Huntrule TeamWindowsdns-clientMedium485Free2024-08-23Windows Process Creation: BCP.EXE Used to Export SQL Data
Flags Windows executions of bcp.exe where command-line options indicate MSSQL data export via out/queryout.
Omar Khaled (@beacon_exe), MahirAli Khan (in/mahiralikhan), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium183Free2024-08-20Windows Process Masquerading as svchost.exe via Binary Name and Location
Alerts on svchost.exe-named processes launched from non-standard paths with OriginalFileName svchost.exe.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh511Free2024-08-07Windows File Access to Cryptocurrency Wallet Keystores by Uncommon Processes
Alerts on access to Ethereum/Bitcoin-style wallet files from non-standard processes on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_accessMedium419Free2024-07-29Windows Process Creation Ending in .exe With No Image Name
Flags Windows process creation events where the .exe path exists but the image name is missing, indicating possible stealth or evasion.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium163Free2024-07-23Windows: Detect execution of renamed BOINC.exe binary
Flags renamed BOINC executables on Windows by matching OriginalFileName=BOINC.exe when the executed image name differs.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium518Free2024-07-23PowerShell Launch With --headless From Conhost.exe on Windows
Flags headless ConHost launching PowerShell on Windows based on process name and command-line arguments.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium162Free2024-07-23Windows: Uncommon Process Access to Microsoft Teams Cookies or Local Storage leveldb
Alerts on access to Teams Cookies or leveldb files by processes other than Teams.exe on Windows.
"@SerkinValery, Huntrule Team"Windowsfile_accessMedium141Free2024-07-22Windows COM CLSID Hijacking via Registry Default InprocServer32/LocalServer32 Modification
Detects registry changes to COM CLSID Default InprocServer32/LocalServer32 values that point to suspicious locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh423Free2024-07-16Windows Process Creation: Renamed Microsoft Teams Executable Launch
Alerts when Microsoft Teams binaries are launched under renamed executable names on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium281Free2024-07-12Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Alerts when DsrmAdminLogonBehavior registry value is changed on Windows, except the default DWORD 0x00000000.
Nischal Khadgi, Huntrule TeamWindowsregistry_setHigh502Free2024-07-11Windows Process Execution of BitLockerToGo.EXE
Alerts on Windows execution of BitLockerToGo.exe, a rarely used BitLocker To Go component for portable drive encryption.
Josh Nickels, mttaggart, Huntrule TeamWindowsprocess_creationLow4010Free2024-07-11Windows DLL Sideloading Suspected for ms<wbr>corsvc.dll via ImageLoad
Alerts on non-standard loads of msocrsvc.dll, a potential DLL sideloading opportunity on Windows.
Wietze Beukema, Huntrule TeamWindowsimage_loadMedium183Free2024-07-11Windows DLL Sideloading via MpSvc.dll Image Load Anomaly
Flags Windows module loads of MpSvc.dll outside typical Defender/WinSxS locations that may indicate DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema, Huntrule TeamWindowsimage_loadMedium337Free2024-07-11Potential DLL Sideloading: Image Load of DbgModel.dll on Windows
Alerts when a process loads DbgModel.dll from a non-standard path, suggesting possible DLL sideloading.
Gary Lobermier, Huntrule TeamWindowsimage_loadMedium439Free2024-07-11