Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,468 rules
Windows Process Creation: LiveKD Execution Suggesting Potential Memory Dumping
Detects launching LiveKD (livekd.exe/livekd64.exe) on Windows via image path or PE OriginalFileName metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium90Free2023-05-15Windows Process Creation of Kernel Debugger kd.exe
Flags Windows process creations that run kd.exe using image path and OriginalFileName metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium227Free2023-05-15Suspicious Child Process of GoogleUpdate.exe on Windows
Alerts when GoogleUpdate.exe spawns an unexpected child process on Windows, using parent/child image telemetry and allowlisting common Google updaters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2023-05-15Windows Process Creation: certutil.exe Encodes Files to Base64 in Suspicious Paths
Alert on certutil.exe running with -encode when the command line references files under suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh120Free2023-05-15Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions
Alert on certutil.exe -encode activity that targets files with suspicious extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2023-05-15Windows DLL Sideloading: goopdate.dll Loaded from Nonstandard Paths
Alerts when goopdate.dll is loaded from non-standard locations, suggesting possible DLL sideloading behavior on Windows.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium443Free2023-05-15Windows RoboForm DLL Sideloading via ImageLoaded roboform.dll/roboform-x64.dll
Alerts on loaded roboform*.dll modules on Windows when module loading is not matched to expected RoboForm binaries.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium447Free2023-05-14Windows Certificate Export from Local Certificate Store (Event ID 1007)
Flags Windows events where a certificate is exported from the local certificate store via Certificate Services client telemetry.
Zach Mathis, Huntrule TeamWindowscertificateservicesclient-lifecycle-systemMedium123Free2023-05-13Windows CAPI2 Event 70: Certificate Private Key Acquired
Detects when Windows CAPI2 logs that a process acquired a certificate private key (EventID 70).
Zach Mathis, Huntrule TeamWindowscapi2Medium151Free2023-05-13Windows Excel Loads .XLL Add-in from Uncommon File Paths
Flags Excel loading .xll add-ins from uncommon directories based on image load paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium93Free2023-05-12Windows: WinSxS .exe Creation Triggered by Non-System Process
Flags .exe creation in C:\Windows\WinSxS\ when the creating process is not from standard system directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium113Free2023-05-11PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh235Free2023-05-09Windows: New PowerShell Module Files Created by Non-PowerShell Processes
Detects new PowerShell module files written into Modules directories by processes other than expected PowerShell hosts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium141Free2023-05-09Windows PowerShell Module File Creation via PowerShell Processes
Alert when PowerShell creates module-related files under WindowsPowerShell or PowerShell 7 module directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow152Free2023-05-09Windows PowerShell dropping a .ps1 script from powershell.exe or pwsh.exe
Alerts when PowerShell creates a dropped .ps1 script file on Windows, excluding common benign temp and test outputs.
frack113, Huntrule TeamWindowsfile_eventLow374Free2023-05-09