Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,468 rules
Windows WerFault ReflectDebugger Registry Key Value Targeting
Flags registry set events targeting WerFault ReflectDebugger under Windows Error Reporting Hangs for potential persistence abuse.
X__Junior, Huntrule TeamWindowsregistry_setHigh141Free2023-05-18PowerShell Certificate Export Cmdlets in Windows Process Creation
Flags PowerShell command lines invoking certificate export cmdlets (Export-PfxCertificate/Export-Certificate) on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium438Free2023-05-18Windows WWlib.DLL sideloading via Office process loading behavior
Alert on Windows image-load events where winword-associated processes load wwlib.dll outside expected Office paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium213Free2023-05-18Windows CreateStreamHash: Suspicious Embedded File Download Indicators via .zip TLD
Flags Windows downloads indicating .zip/ plus ':Zone' in target filenames for risky executable or script extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh162Free2023-05-18Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments
Flags rundll32.exe launches with command-line ordinal obfuscation patterns.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2023-05-17Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2023-05-17Windows Process Creation: cloudflared Tunnel Execution with Config and Credentials Flags
Alerts on Windows processes running cloudflared tunnels with config and token/credential flags.
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium361Free2023-05-17Windows: Detect cloudflared tunnel cleanup command execution
Flags Windows executions of cloudflared with tunnel cleanup and connector/config parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium332Free2023-05-17Windows Registry: Internet Explorer DisableFirstRunCustomize Set via Explorer or ie4uinit
Alerts on Windows registry writes to Internet Explorer DisableFirstRunCustomize that change first-run wizard customization states.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium315Free2023-05-16Windows LiveKD Kernel Memory Dump Attempt via "-m" Flag
Flags LiveKD executions with the "-m" option that may trigger kernel memory dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2023-05-16Windows LiveKD Driver File Creation by Uncommon Process Image
Alerts when LiveKdD.SYS is created by a process other than livekd.exe/livek64.exe on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh111Free2023-05-16Windows LiveKD Driver Creation via LiveKdD.SYS and LiveKD Executable Launch
Detects creation of LiveKdD.SYS in the Windows drivers directory by LiveKD executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium103Free2023-05-16Windows: LiveKD kernel memory dump file creation (livekd.dmp)
Flags creation of C:\Windows\livekd.dmp, a default LiveKD kernel memory dump file name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh317Free2023-05-16Windows Wscript/Cscript Executes Files with Uncommon Non-Script Extensions
Flags wscript.exe/cscript.exe launching files named with uncommon non-script extensions via command-line content.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-05-15Suspicious rundll32/regsvr32/msiexec Child Process from Windows Script Hosts (cscript/wscript)
Alerts on wscript/cscript spawning suspicious child processes or scripts that invoke rundll32/regsvr32/msiexec.
Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'), Huntrule TeamWindowsprocess_creationMedium134Free2023-05-15