Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows AddInUtil.exe Executed with Suspicious AddInRoot or PipelineRoot Parameters
Alerts on AddInUtil.exe runs using uncommon AddInRoot/PipelineRoot values targeting Temp, Desktop, Downloads, or public user paths.
Nasreddine Bencherchali (Nextron Systems), Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsprocess_creationHigh102Free2023-09-18Windows network connections initiated by AddinUtil.exe
Alerts on network connections initiated by Addinutil.exe, which is uncommon for this utility on Windows.
Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri), Huntrule TeamWindowsnetwork_connectionHigh431Free2023-09-18Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths
Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-09-15Windows Diskshadow Script Mode Executes Script File with Uncommon .txt Extension
Alerts when diskshadow.exe runs with -s script mode and the script path/command includes an uncommon extension like .txt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium341Free2023-09-15Suspicious Child Process Spawned by Diskshadow.exe (Windows Process Creation)
Alerts on process creation where Diskshadow.exe spawns certutil, cscript, mshta, PowerShell, regsvr32, rundll32, or wscript.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium110Free2023-09-15Windows: Headless Chromium Browser Execution via --headless
Alerts on headless Chromium-based browser launches on Windows using the "--headless" command-line flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-09-12Windows Process Creation: wmic.exe call terminate Attempt
Alerts on wmic.exe being executed with “call terminate”, indicating an attempt to terminate a process on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2023-09-11Windows Process Creation: Execution of Renamed curl.exe via PE Metadata
Alerts on Windows process launches whose PE metadata matches curl.exe even when the executable image is renamed.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium469Free2023-09-11Windows Chromium Headless Execution with Mockbin/Mocky URL
Alerts when a Chromium-based browser runs headless on Windows with a mockbin-like URL in the command line.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2023-09-11Windows Suspicious Creation of .dmp/.hdmp Files by Shell or Script Hosts
Alerts on .dmp/.dump/.hdmp file creation by common Windows shells and scripting engines.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium172Free2023-09-07Windows Registry: Enabled TLS 1.0 or TLS 1.1 via SCHANNEL Protocols Enabled=1
Flags registry changes that set SCHANNEL TLS 1.0/1.1 Enabled to 1 on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium243Free2023-09-05Windows Registry ZoneMap ProtocolDefaults Downgraded to My Computer for HTTP/HTTPS
Flags IE/Windows ZoneMap changes setting HTTP/HTTPS ProtocolDefaults DWORD 0x00000000 to the My Computer zone.
Nasreddine Bencherchali (Nextron Systems), Michael Haag (idea), Huntrule TeamWindowsregistry_setHigh301Free2023-09-05Suspicious CommandLine Parameters for Electron Apps on Windows
Alerts on Electron app execution with command-line flags consistent with subprocess and renderer/utility launching behavior.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2023-09-05Windows Process Creation: IE ZoneMap ProtocolDefaults downgraded to My Computer for HTTP/HTTPS
Flags Windows command lines that set IE ZoneMap ProtocolDefaults for HTTP to the My Computer (zone 0) trust level.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh268Free2023-09-05Windows: Detect VMMap loading a signed dbghelp.dll from C:\Debuggers\
Alerts on vmmap.exe/vmmap64.exe loading a signed dbghelp.dll from C:\Debuggers, consistent with potential DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium133Free2023-09-05