Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows: wordpad.exe Initiated Network Connections on Uncommon Ports
Alerts when wordpad.exe initiates outbound connections on destination ports outside common C2-related ports.
X__Junior (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium141Free2023-07-12Windows Office Apps Initiating Network Connections to Non-Common Ports
Alerts on network connections initiated by Windows Office apps to destination ports not in the common port set.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium437Free2023-07-12Windows: Suspicious File Creation in Fake RECYCLER.BIN Staging Folders
Alerts on Windows file writes involving RECYCLERS.BIN\ or RECYCLER.BIN\ paths often used for staging.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh408Free2023-07-12Windows DLL Sideloading via Abusable DLLs Loaded from Suspicious Locations
Flags Windows module loads of specific abusable DLL names from public, temp, or user folders consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh445Free2023-07-11Windows: Recon command output piped to findstr.exe
Alerts on Windows command lines running recon commands whose output is filtered with findstr.exe.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium91Free2023-07-06Windows process creation: WerFault.exe executed with -pr flag
Alerts when WerFault.exe is launched with the -pr argument, potentially indicating ReflectDebugger-based execution.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-06-30Windows PowerShell Decryption-Like Activity Involving .LNK File Processing
Identifies PowerShell runs that enumerate and process *.lnk content using byte-level reads/writes consistent with decryption staging.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2023-06-30Windows Process Execution of curl.exe with --insecure Flag
Flags curl.exe launched with --insecure/-k to disable TLS certificate verification.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2023-06-30Windows Registry: Uncommon Microsoft Office Trusted Location Path Added
Alerts on registry changes adding non-standard Microsoft Office Trusted Location paths that could undermine macro security.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2023-06-21Windows Registry TrustRecords Change for Macro-Enabled Documents in Suspicious Paths
Alert on Windows registry changes to Office TrustRecords where trusted-document paths fall in suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh151Free2023-06-21Windows: Office Executable Running a Document from Trusted Template/Startup Paths
Alerts when Office apps are launched with command lines pointing to documents under Office template/Startup paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2023-06-21Windows rundll32.exe Using ShellExecute via ShellDispatch.dll Functionality
Alerts on rundll32.exe command lines referencing RunDll_ShellExecuteW, suggesting ShellDispatch.dll ShellExecute-based execution.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2023-06-20Windows ShellDispatch.dll DLL Sideloading via Image Load Monitoring
Alerts on suspicious loads of ShellDispatch.dll on Windows when not occurring in expected temp directories.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium152Free2023-06-20Windows DLL side-loading via appverifUI.dll image loads
Alerts when appverifUI.dll is loaded on Windows from unexpected paths, a common DLL sideloading technique.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh214Free2023-06-20Windows Security 4719: Important Audit Policy Categories Disabled
Alerts on Windows Security 4719 indicating auditing was disabled for important security event subcategories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh186Free2023-06-20