Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,461 rules
Potential DLL Sideloading: Image Load of DbgModel.dll on Windows
Alerts when a process loads DbgModel.dll from a non-standard path, suggesting possible DLL sideloading.
Gary Lobermier, Huntrule TeamWindowsimage_loadMedium439Free2024-07-11Windows: Detect regedit.exe creating a PDF file
Alerts when RegEdit.exe creates a .pdf file on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh326Free2024-07-08Windows Registry: DisableHypervisorEnforcedPagingTranslation Set to 1
Alerts when Windows disables Hypervisor Enforced Paging Translation by setting DisableHypervisorEnforcedPagingTranslation to 1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2024-07-05Windows Registry: EnablePeriodicBackup value set for periodic system hive backups
Alerts on enabling the Windows registry setting that triggers periodic system hive backups to RegBack on restarts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium182Free2024-07-01Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Flags and image indicators for RemoteKrbRelay execution on Windows, including relaying-related command-line actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2024-06-27Windows File Drop Indicators for RemoteKrbRelay SMB Relay Secret Dump Module
Alerts on creation of RemoteKrbRelay-specific temp files used to stage secrets dump outputs on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh354Free2024-06-27Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule TeamWindowsprocess_creationHigh261Free2024-06-26SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2024-06-26Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh191Free2024-06-26Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.
Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh288Free2024-06-26Windows Process Execution: LaZagne Credential Dumping Utility (lazagne.exe)
Flags Windows process launches consistent with running LaZagne (lazagne.exe) for credential and password recovery.
Nasreddine Bencherchali, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2024-06-24Windows Network Connections to azurewebsites.net from Non-Browser Processes
Alerts on outbound connections to azurewebsites.net started by non-browser processes on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium222Free2024-06-24Windows File Creation: System DLL Named .dll in Uncommon Locations
Alerts on creation of .dll files named like system DLLs in unexpected Windows directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium183Free2024-06-24Windows DNS Queries to azurewebsites.net From Non-Browser Processes
Alerts on DNS queries to azurewebsites.net from processes other than common browsers, using Windows DNS query and process image telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryMedium257Free2024-06-24Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Alerts on initiated outbound connections from Windows hosts to LocaltoNet/.localtonet.com tunneling domains.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsnetwork_connectionHigh173Free2024-06-17