Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows sc.exe Service Security Descriptor Tampering (sdset)
Detects sc.exe executions using sdset to modify service security descriptors, enabling stealthy service tampering.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-02-28Windows sc.exe Service Security Descriptor Changes via sdset
Alerts on sc.exe sdset activity that modifies a service security descriptor to grant access to targeted principals.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-02-28Windows Firewall Exception Rule Added for Application in Suspicious Path
Flags new Windows Defender Firewall exception rules for apps located in Temp/PerfLogs/Public/Tasks-like directories.
frack113, Huntrule TeamWindowsfirewall-asHigh81Free2023-02-26Windows: Mounting Internet Hosted WebDAV Shares via net.exe
Alerts on net.exe (net1.exe) commands that mount an HTTP/WebDAV network share.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-02-21Windows New Service Creation via sc.exe
Flags sc.exe service creation commands containing create and binPath on Windows, excluding Dropbox-launched cases.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow438Free2023-02-20PowerShell Creates Windows Service via New-Service and -BinaryPathName
Flags PowerShell command lines that use New-Service with -BinaryPathName to create a Windows service.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow372Free2023-02-20Windows Registry Persistence Indicators in Event Viewer Events.asp Links
Flags Windows registry entries that reference Event Viewer Events.asp redirection URLs, excluding known benign svchost/GPO templates.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium151Free2023-02-17Windows suspicious vsstrace.dll image load by uncommon executables
Alert on vsstrace.dll module loads from processes outside common Windows/system paths.
frack113, Huntrule TeamWindowsimage_loadMedium60Free2023-02-17Windows Tomcat Log File Deletion Indicating Possible Forensic Evidence Destruction
Flags Windows file deletions matching Tomcat log paths and common Catalina/localhost access log filename patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium453Free2023-02-16Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)
Alerts on Windows process launches with command lines containing Unicode U+202E to support right-to-left text obfuscation.
Micah Babinski, @micahbabinski, Swachchhanda Shrawan Poudel (Nextron Systems), Luc Génaux, Huntrule TeamWindowsprocess_creationHigh82Free2023-02-15Windows: certutil.exe ExportPFX certificate export via -exportPFX flag
Flags certutil.exe executions on Windows that include the -exportPFX argument to export certificate material.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium384Free2023-02-15Windows: certutil.EXE Downloading Files from File-Sharing Domains via Suspicious Flags
Alert when certutil.exe is run with URL/download flags targeting common file-sharing domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh150Free2023-02-15Windows certutil.exe Download from Direct IP Using URL/IP-Related Flags
Alerts when certutil.exe is launched with direct-IP download indicators and download-capable certutil flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2023-02-15Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
Alerts on certutil.exe runs with URL/HTTP-related flags indicative of remote file download.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-02-15Windows certutil.exe Base64/Hex Decode via -decode or -decodehex Flags
Flags certutil.exe use for decoding base64 or hex data via -decode or -decodehex on Windows.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh132Free2023-02-15