Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows: CertOC.exe Loading a DLL from User-Writable Paths via -LoadDLL
Alerts on CertOC.exe using -LoadDLL with DLLs from temp/user-writable directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-02-15Windows PowerShell Console History File Deleted (PSReadLine)
Flags deletion of the PowerShell PSReadLine ConsoleHost_history.txt file, which can remove command history evidence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium102Free2023-02-15Windows Event Log EVTX File Deletion in winevt\Logs
Flags deletion of Windows Event Log .evtx files under System32\winevt\Logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium313Free2023-02-15Windows WMIC Remote Query Execution via /node
Identifies remote WMIC queries on Windows by matching WMIC execution with /node: in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-02-14Windows WMIC.exe Service Reconnaissance via Remote Service Queries
Flags WMIC.exe commands containing service-related reconnaissance strings while excluding stop/start service manipulation.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2023-02-14Windows WMIC.exe Product Class Reconnaissance via Security Product Queries
Detects wmic.exe being used to enumerate firewall, antivirus, and antispyware product classes.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium1910Free2023-02-14Windows WMIC Product Reconnaissance via Firewall/AV Enumeration
Alerts on wmic.exe executions with command lines consistent with Windows product enumeration for reconnaissance.
Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium154Free2023-02-14Windows wmic.exe Hardware Model Reconnaissance Using csproduct
Flags wmic.exe executions that include "csproduct" to query hardware model/vendor details.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium359Free2023-02-14Windows execution of LocalPotato POC (LocalPotato.exe with specific PE/CLI traits)
Detects LocalPotato.exe process execution on Windows using image path, typical CLI parameters, and known imphash values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2023-02-14Windows Suspicious Execution of Regasm/Regsvcs With Uncommon Command-Line Extension
Flags Regasm.exe/Regsvcs.exe runs that include unusual extensions in the command line, which may indicate stealthy misuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium241Free2023-02-13Windows: Filter Driver Unload via fltMC.exe
Flags fltMC.exe executions that include "unload" to indicate potential filter driver unloading for defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2023-02-13Windows: Suspicious Executable Created in Temp by OneNote (onenote.exe/onenotem.exe/onenoteim.exe)
Alerts when OneNote creates files in Temp\OneNote with script/executable extensions on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh141Free2023-02-09Windows Registry: Outlook EnableUnsafeClientMailRules Set to 1
Alerts when Outlook’s EnableUnsafeClientMailRules registry value is enabled (DWORD 0x1), reducing mailbox macro/script protections.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh112Free2023-02-08Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Alerts on Windows executions referencing gatherNetworkInfo.vbs in process command lines, indicative of potential discovery activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh295Free2023-02-08Windows: Outlook loads outlvba.dll (VBA for Outlook add-in) via image loading
Alerts on outlvba.dll being loaded by outlook.exe, indicating VBA add-in execution within Outlook.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium152Free2023-02-08