Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows ImageLoad: Uncommon Process Loads RstrtMgr.dll (Restart Manager)
Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.
Luc Génaux, Huntrule TeamWindowsimage_loadLow141Free2023-11-28Windows Image Load of RstrtMgr.dll by Suspicious Path or User Content
Alerts on RstrtMgr.dll loading from suspicious path contexts using Windows image load telemetry.
Luc Génaux, Huntrule TeamWindowsimage_loadHigh122Free2023-11-28Python-Based Tool LSASS Process Access for Credential Dumping (Windows)
Alerts on process-access attempts to lsass.exe with a Python-related call trace and high granted access.
Bhabesh Raj, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_accessHigh2410Free2023-11-27Windows HackTool Process Access: Detect Access by Common Tool Image Names
Alerts on Windows process access events initiated by processes whose image names match common credential/dumping hack tools.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_accessHigh344Free2023-11-27wusa.exe Execution with Parent in Suspicious Windows Paths
Alerts when wusa.exe is spawned by a parent running from common suspicious Windows directories, excluding .msu-related noise.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh422Free2023-11-26Windows Registry IME File Value Used from Suspicious Paths
Alerts on Windows keyboard layout "Ime File" registry entries pointing to suspicious writable directory paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2023-11-21Windows Registry: Uncommon IME File Value in Keyboard Layouts Path
Alerts on Control\Keyboard Layouts\ registry values named "Ime File" that reference non-.ime extensions.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setHigh228Free2023-11-21Windows Network Connections to Visual Studio Code Tunnels Domain
Alerts on initiated network connections to .tunnels.api.visualstudio.com from a Windows process.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium112Free2023-11-20Windows Network Connections to *.devtunnels.ms
Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium111Free2023-11-20Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
Alerts when excel.exe spawns foxprow.exe, schdplus.exe, or winproj.exe, consistent with suspicious Excel DCOM automation activity.
Aaron Stratton, Huntrule TeamWindowsprocess_creationHigh143Free2023-11-13Windows: Command-Line Use of ms-appinstaller Protocol Handler for File Downloads
Alerts on Windows command lines invoking ms-appinstaller with an http source, indicating potential remote file download behavior.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium262Free2023-11-09Windows msxsl.exe Execution with HTTP Keyword in Command Line
Flags execution of msxsl.exe when the command line includes an HTTP URL indicator.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh70Free2023-11-09Windows: File Download via msedge_proxy.exe Using HTTP/HTTPS URLs
Flags msedge_proxy.exe executions that include HTTP/HTTPS URLs, consistent with arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium168Free2023-11-09Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS
Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh383Free2023-11-09Windows Registry: Disabling Antivirus Filter Driver on Dev Drive via FltmgrDevDriveAllowAntivirusFilter
Detects registry changes disabling antivirus minifilter inspection on a Dev Drive by setting the allow setting to 0x0.
"@kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsregistry_setHigh333Free2023-11-05