Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows Code Integrity Operational: Unsigned Image Loaded
Alerts on Windows Code Integrity detecting that an unsigned image was loaded (Event ID 3037).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh111Free2023-06-06Windows Code Integrity Unsigned Kernel Module Loaded (Event ID 3001)
Alerts on Windows Code Integrity reporting an unsigned kernel module load via Event ID 3001.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh289Free2023-06-06Windows Code Integrity: Revoked Signed Image Loaded (Event 3032/3035)
Alerts on Code Integrity events showing a revoked signed image was loaded, including debugger-allowed cases.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh143Free2023-06-06Windows Code Integrity blocks image load when signing certificate is revoked (Event ID 3036)
Alerts on Windows Code Integrity Event ID 3036 when image loads are blocked because the signing certificate is revoked.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh122Free2023-06-06Windows Code Integrity: Revoked Kernel Driver Loaded (Event 3021/3022)
Alerts when Windows Code Integrity reports a revoked kernel driver/module loaded (including debugger-allowed cases) via Event IDs 3021/3022.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh179Free2023-06-06Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Flags Code Integrity Operational events where Windows blocks loading a revoked (untrusted) driver certificate.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh147Free2023-06-06Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
Alerts on Windows Code Integrity Event ID 3104 when a disallowed file is blocked for protected processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh113Free2023-06-06Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript
Alerts on suspicious renamed AutoIt2/AutoIt3 execution based on command-line parameters plus known hashes and original file names.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2023-06-04Windows DLL Sideloading via SmadHook32c.dll and SmadHook64c.dll Loads
Alerts on non-standard loads of SmadHook32c.dll/SmadHook64c.dll on Windows, consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh181Free2023-06-01Windows: PowerShell Core DLL Loaded by Office Application
Flags Office apps that load System.Management.Automation DLLs associated with PowerShell Core.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium143Free2023-06-01Windows: Detect Loading amsi.dll by LOLBIN Processes
Alert on amsi.dll DLL loads initiated by ExtExport.exe, Odbcconf.exe, or Rundll32.exe on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium326Free2023-06-01Windows File Events: PSScriptPolicyTest Script Creation by Uncommon Process
Alert on __PSScriptPolicyTest_ PowerShell script file creation when the writing process is not an expected PowerShell component.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium203Free2023-06-01Windows Scripting Engines Spawning regsvr32.exe via Parent Process Execution
Flags common script/command interpreters launching regsvr32.exe on Windows, a potential proxy execution behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium171Free2023-05-26Windows regsvr32 Execution from Suspicious DLL Paths
Alerts on regsvr32 runs whose command line references a DLL in highly suspicious Windows directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-05-26Windows regsvr32 Execution with DLL Path in Common Temporary/Public Directories
Alert on regsvr32.exe runs whose command line points to DLLs in Temp/Public-style directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium445Free2023-05-26