Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows Utility Loads Unsigned DLL (ImageLoad)
Flags DLL loads by InstallUtil/RegAsm/RegSvcs/regsvr32/rundll32 when the loaded DLL is unsigned or untrusted.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadMedium143Free2024-02-28Windows ScreenConnect Service Web Shell Execution via cmd.exe or csc.exe
Alert on ScreenConnect.Service.exe spawning cmd.exe or csc.exe, consistent with potential web shell execution on Windows.
Jason Rathbun (Blackpoint Cyber), Huntrule TeamWindowsprocess_creationHigh131Free2024-02-26Windows DNS Queries to update.onelaunch.com by OneLaunch.exe
Flags DNS requests to update.onelaunch.com from OneLaunch.exe on Windows.
Josh Nickels, Huntrule TeamWindowsdns_queryLow132Free2024-02-26Windows Suspicious Wget.exe Downloads From IP to Common Staging Paths
Flags wget.exe on Windows downloading from an IP over HTTP and saving to common staging/user directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2024-02-23Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2024-02-23Windows SimpleService Execution via Remote Access Tool Wrapper Paths
Flags Windows processes running SimpleService.exe from remote access tool wrapper directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium182Free2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2024-02-23Windows Module Usage Enumeration via tasklist.exe -m rdpcorets.dll
Flags tasklist.exe module enumeration (-m) targeting rdpcorets.dll to identify the owning process.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium182Free2024-02-12Windows sc.exe Service Query for termservice Enumeration
Alerts on sc.exe service querying that references termservice on Windows.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationLow321Free2024-02-12Windows: AnyDesk Execution Using Revoked Certificate Versions
Detects AnyDesk.exe execution on Windows when the file version matches known revoked-certificate releases (excluding uninstall/remove).
Sai Prashanth Pulisetti, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium433Free2024-02-08Windows iexpress.exe Creates Self-Extracting Binaries Using SED Files From Suspicious Paths
Flags suspicious use of Windows iexpress.exe to create self-extracting packages via SED directives from uncommon/temp paths.
Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh245Free2024-02-05Windows: Alerts on Creation of .sed Self-Extraction Directive File
Flags creation of newly created .sed directive files on Windows, which can be used for self-extracting package abuse.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_executable_detectedMedium251Free2024-02-05Windows Self Extraction Directive (.sed) File Created in Suspicious Paths
Alerts on .sed directive file creation under ProgramData/Temp/Tasks paths on Windows, consistent with iExpress-based packaging abuse.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_eventMedium153Free2024-02-05Windows WMI Disk and Volume Discovery via WMIC.exe
Flags WMIC.exe process executions that query Win32 logical disk and volume listing details.
Stephen Lincoln '@slincoln-aiq' (AttackIQ), Huntrule TeamWindowsprocess_creationMedium464Free2024-02-02Windows SharpMove (.NET) Execution via SharpMove.exe and Action Command-Line Flags
Alerts on SharpMove.exe process execution with command-line actions for DCOM, WMI VBS, and task scheduler.
Luca Di Bartolomeo (CrimpSec), Huntrule TeamWindowsprocess_creationHigh81Free2024-01-29