Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows SimpleService Execution via Remote Access Tool Wrapper Paths
Flags Windows processes running SimpleService.exe from remote access tool wrapper directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium172Free2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2024-02-23Windows Module Usage Enumeration via tasklist.exe -m rdpcorets.dll
Flags tasklist.exe module enumeration (-m) targeting rdpcorets.dll to identify the owning process.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium152Free2024-02-12Windows sc.exe Service Query for termservice Enumeration
Alerts on sc.exe service querying that references termservice on Windows.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationLow321Free2024-02-12Windows: AnyDesk Execution Using Revoked Certificate Versions
Detects AnyDesk.exe execution on Windows when the file version matches known revoked-certificate releases (excluding uninstall/remove).
Sai Prashanth Pulisetti, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium423Free2024-02-08Windows iexpress.exe Creates Self-Extracting Binaries Using SED Files From Suspicious Paths
Flags suspicious use of Windows iexpress.exe to create self-extracting packages via SED directives from uncommon/temp paths.
Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh245Free2024-02-05Windows: Alerts on Creation of .sed Self-Extraction Directive File
Flags creation of newly created .sed directive files on Windows, which can be used for self-extracting package abuse.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_executable_detectedMedium251Free2024-02-05Windows Self Extraction Directive (.sed) File Created in Suspicious Paths
Alerts on .sed directive file creation under ProgramData/Temp/Tasks paths on Windows, consistent with iExpress-based packaging abuse.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_eventMedium123Free2024-02-05Windows WMI Disk and Volume Discovery via WMIC.exe
Flags WMIC.exe process executions that query Win32 logical disk and volume listing details.
Stephen Lincoln '@slincoln-aiq' (AttackIQ), Huntrule TeamWindowsprocess_creationMedium454Free2024-02-02Windows SharpMove (.NET) Execution via SharpMove.exe and Action Command-Line Flags
Alerts on SharpMove.exe process execution with command-line actions for DCOM, WMI VBS, and task scheduler.
Luca Di Bartolomeo (CrimpSec), Huntrule TeamWindowsprocess_creationHigh81Free2024-01-29Windows EDRSilencer Execution via Filtering Platform FilterName Change
Detects Filtering Platform custom outbound filter additions associated with potential EDRSilencer execution on Windows.
Thodoris Polyzos (@SmoothDeploy), Huntrule TeamWindowssecurityHigh408Free2024-01-29Windows Process Creation: SOAPHound Execution via AD Data Collection Command-Line Arguments
Flags SOAPHound execution on Windows by detecting command-line arguments used for Active Directory data collection.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh349Free2024-01-26Uncommon ADWS (Port 9389) Connections from Non-Standard Windows Binaries
Alerts on unexpected process-to-ADWS (TCP/9389) connections on Windows to highlight potential directory discovery.
"@kostastsale, Huntrule Team"Windowsnetwork_connectionMedium111Free2024-01-26Windows Code Page Change via mode.com Selecting Russian Code Pages
Alerts when mode.com is used to set console code pages to Russian values (1251 or 866).
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium232Free2024-01-17Windows: Detect renamed PingCastle binary execution via PE metadata and scanner command-line
Flags Windows processes that look like renamed PingCastle executables using PE original file names and PingCastle scanner/healthcheck arguments.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2024-01-11