Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows: VSDiagnostics.EXE started with launch parameters to proxy arbitrary binaries
Alerts when VSDiagnostics.exe is started with launch arguments that may be used to proxy other binaries on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2023-08-03Windows: Detect ImageLoad of vivaldi_elf.dll for Potential DLL Sideloading
Flags ImageLoad events for vivaldi_elf.dll on Windows that are not consistent with an expected Vivaldi app path.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium365Free2023-08-03Windows DLL Sideloading via mfdetours.dll using mftrace.exe
Alerts on mfdetours.dll loads that may indicate DLL sideloading outside the expected Windows Kits location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium60Free2023-08-03Windows ImageLoad DLL Sideloading: EACore.dll
Alerts on Windows loading of EACore.dll that may indicate DLL sideloading, excluding a specific EA Desktop legitimate case.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh102Free2023-08-03Windows DLL sideloading via AVKkid.dll image loads
Identifies suspicious AVKkid.dll loads on Windows that may indicate DLL sideloading, excluding a specific likely legitimate path pattern.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium121Free2023-08-03Windows Registry Key Abuse via Provisioning Commands for Proxy Binary Execution
Flags registry modifications to the Provisioning Commands key path that may enable indirect execution via Provlaunch.exe.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setHigh81Free2023-08-02Windows Amazon SSM Agent Process Creation with Registration and Code Parameters
Alerts on amazon-ssm-agent.exe starting with -register, -code, -id, and -region parameters on Windows.
Muhammad Faisal, Huntrule TeamWindowsprocess_creationMedium143Free2023-08-02Windows AppCompatFlags InstalledSDB New Shim Database in Non-Default Path
Flags persistence attempts where a shim database is registered via InstalledSDB with a non-default DatabasePath on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh124Free2023-08-01Windows Registry: New AppCompatFlags custom shim databases targeting system processes
Alerts on Windows registry writes to AppCompatFlags Custom shim paths targeting common system processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh303Free2023-08-01Windows sdbinst.exe Installing Shim Database with Uncommon Extension
Flags sdbinst.exe process executions consistent with installing shim databases using uncommon .sdb command-line patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium464Free2023-08-01Windows VMMap Loading Unsigned dbghelp.dll from C:\Debuggers\dbghelp.dll
Alerts when VMMap loads an unsigned dbghelp.dll from C:\Debuggers, suggesting DLL sideloading on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh142Free2023-07-28Windows CreateRemoteThread in mstsc.exe From Suspicious Source Paths
Alerts when mstsc.exe creates remote threads from processes running out of common suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_remote_threadHigh249Free2023-07-28Windows: Alert on wget.exe downloading files from an IP with output flags
Flags Windows wget.exe usage to download HTTP URLs from IPs and write outputs to script/binary extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3510Free2023-07-27Windows: curl.exe Local File Read via file:/// Command Line
Flags curl.exe runs that include file:/// to access local files on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-07-27Windows: Curl.exe Insecure Proxy/DOH Transfer Flags
Flags curl.exe with --proxy-insecure and/or --doh-insecure during Windows process execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-07-27