Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Suspicious curl.exe File Downloads From Direct IP Addresses on Windows
Alerts on Windows curl.exe commands downloading from an IP address with HTTP/S and suspect file extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2023-07-27Windows Process Execution: curl.exe with Custom User-Agent Header
Flags Windows executions of curl.exe that include a User-Agent header in the command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-07-27Windows Process Execution: curl.exe Saving Cookies via -c / --cookie-jar
Flags curl.exe commands that save cookie jar data using -c/--cookie-jar on Windows process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium341Free2023-07-27Windows Terminal settings.json modified by uncommon process
Alerts on Windows Terminal settings.json changes made by an uncommon command-line or script host process.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium92Free2023-07-22Windows Sysmon FileExecutableDetected (Event ID 29) Alerts on New Executable Files
Alerts on any Sysmon Event ID 29 indicating a new monitored executable file was created on Windows.
frack113, Huntrule TeamWindowssysmonMedium478Free2023-07-20Sysmon FileBlockShredding Policy Violations (Event ID 28) on Windows
Alerts on Sysmon Event ID 28 when file shredding is blocked by the configured shredding policy on Windows.
frack113, Huntrule TeamWindowssysmonHigh407Free2023-07-20Windows Process Creation: schtasks.exe Creating Scheduled Task Launching Registry-Stored PowerShell Payload
Flags schtasks.exe /Create scheduled tasks that launch PowerShell decoding and executing a base64 payload retrieved from Windows Registry.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-07-18Windows netsh.exe Advanced Firewall Rule Set Modification
Flags netsh.exe command lines that invoke advfirewall firewall set to modify existing Windows firewall rule properties.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2023-07-18Windows Process Creation: One-liner cmd.exe CommandLine with ping and copy
Alerts when cmd.exe runs a one-liner that includes both ping and copy with expected options.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2023-07-18Windows PowerShell Script Modifies File Permissions with Set-Acl
Flags PowerShell scripts that call Set-Acl to change ACL permissions on a specified path.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow80Free2023-07-18Windows PowerShell WMI Win32_NTEventlogFile Calls with Event Log Tampering Methods
Flags PowerShell calling Win32_NTEventlogFile WMI methods commonly used to clear, delete, backup, or alter Windows event logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2023-07-13Suspicious PowerShell WMI Win32_NTEventlogFile Usage (Event Log Tampering)
Detects PowerShell scripts calling Win32_NTEventlogFile methods associated with event log deletion, backup, renaming, or permission changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium163Free2023-07-13Windows DLL Sideloading: CCleanerReactivator.dll Loaded from CCleaner Directories
Identifies potential CCleanerReactivator.dll DLL sideloading when loaded by CCleanerReactivator.exe outside expected CCleaner paths.
X__Junior, Huntrule TeamWindowsimage_loadMedium228Free2023-07-13Windows DLL Sideloading via CCleanerDU.dll ImageLoad from CCleaner Folder
Alerts when CCleanerDU.dll is loaded, but the loading image is not CCleaner executables in standard install paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium142Free2023-07-13Windows Process Creation From Fake Recycle.Bin Directories
Alerts on Windows processes launched from fake RECYCLER.BIN / RECYCLERS.BIN folder paths often used for stealth.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh329Free2023-07-12