Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows Virtual Smart Card Created Using TpmVscMgr.EXE
Flags execution of Tpmvscmgr.exe with a create command, indicating creation of a new virtual smart card.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2023-06-15Windows: Detect lodctr.exe Rebuild (-r) Performance Counter Values
Flags lodctr.exe executions with -r, indicating attempts to rebuild performance counter registry values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium131Free2023-06-15Windows VMwareToolBoxCmd.exe Script/Set Execution Used for VM State Persistence
Alerts on VMwareToolBoxCmd.exe launched with script/set flags and command-line hints of a suspicious VM state persistence setup.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-06-14Windows: VMwareToolBoxCmd.exe script/set Used to Configure VM State Persistence
Flags VMwareToolBoxCmd.exe use of 'script' and 'set' parameters consistent with VM state–based persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-06-14Windows DLL Sideloading: waveedit.dll Loaded by Nero WaveEditor
Alerts when waveedit.dll is loaded from an unexpected path, suggesting possible DLL sideloading on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh155Free2023-06-14Windows Registry: ClickOnce Trust PromptingLevel Set to Enabled for Multiple Locations
Alerts on Enabled ClickOnce trust prompting registry changes for Internet and related locations.
"@SerkinValery, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsregistry_setMedium101Free2023-06-12Suspicious Child Process Spawned by ClickOnce Application (Windows)
Alerts when a ClickOnce app under AppData\Local\Apps\2.0\ spawns common script/tool executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-06-12Windows: Uncommon Child Processes Spawned by SndVol.exe
Alerts when SndVol.exe launches unusual child processes, using Windows process creation logs.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-06-09Windows: Potential RjvPlatform.dll DLL Sideloading via SystemResetPlatform.exe from Non-Default Path
Flags SystemResetPlatform.exe loading RjvPlatform.dll from a non-default location, indicating possible DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh171Free2023-06-09Windows: RjvPlatform.dll loaded by SystemResetPlatform.exe from $SysReset path
Alerts on SystemResetPlatform.exe loading RjvPlatform.dll from the $SysReset Framework Stack path on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium2210Free2023-06-09Windows DLL Sideloading Suspicion via edputil.dll Image Load
Alerts on edputil.dll image loads occurring outside standard Windows system directories, suggesting possible DLL side-loading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh112Free2023-06-09Windows DLL Sideloading Indicators: 7za.dll Loaded from Non-Program Files Paths
Alerts when a process loads 7za.dll from a non-Program Files path, indicating potential DLL sideloading.
X__Junior, Huntrule TeamWindowsimage_loadLow186Free2023-06-09Windows ClickOnce Loads Unsigned or Expired Signed Modules from User Apps Path
Alerts when a ClickOnce app loads a module from Apps\2.0 that is unsigned or has an expired signature.
"@SerkinValery, Huntrule Team"Windowsimage_loadMedium258Free2023-06-08Windows Registry COM InProcServer32 Hijack via PSFactory CLSID Default Value
Detects suspicious modifications to a PSFactory COM InProcServer32 (Default) registry value that may enable COM-based persistence.
BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk, Huntrule TeamWindowsregistry_setHigh452Free2023-06-07Windows Code Integrity: Kernel Module Loaded Without WHQL Requirements (Event 3082/3083)
Alerts when Code Integrity logs show loaded kernel modules failing WHQL compliance (Event 3082/3083), excluding selected VMware drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh82Free2023-06-06