Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows: .pub File Creation in Temp or Public Directories
Alerts on creation of .pub files in Temp/Public-like directories on Windows where staging is likely.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium419Free2023-02-08Windows: Suspicious Outlook VbaProject.OTM Macro File Created
High-confidence file creation alert for Microsoft\Outlook\VbaProject.OTM while excluding outlook.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh206Free2023-02-08Windows File Events: VBS gatherNetworkInfo results file creation
Flags Windows file writes under System32\config consistent with gatherNetworkInfo.vbs network reconnaissance output.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium239Free2023-02-08Windows Process Creation: Renamed AutoHotkey Executable via PE Metadata
Detects renamed AutoHotkey executables by correlating process creation events with PE metadata indicators.
Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium132Free2023-02-07Windows nltest.exe Execution for Network Information Discovery
Flags execution of nltest.exe (including nltestrk.exe via OriginalFileName) used for network and domain information discovery.
Arun Chauhan, Huntrule TeamWindowsprocess_creationLow140Free2023-02-03Windows cmdkey.exe Adds Generic Credentials via -g Flag
Flags -g/-u/-p with cmdkey.exe indicate generic credential insertion, which can enable follow-on access.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium464Free2023-02-03Windows OneNote.exe launches cmd/cscript/mshta/PowerShell/wscript with OneNote-exported scripts
Alerts when OneNote.exe spawns common script interpreters to execute OneNote-exported or offline-cache script content.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh90Free2023-02-02Windows: PowerShell Add-AppxPackage Attempt With -AllowUnsigned for AppX Installation
Detects PowerShell Add-AppxPackage usage with -AllowUnsigned to install unsigned AppX packages.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium447Free2023-01-31Windows PowerShell: Add-AppxPackage with -AllowUnsigned for Unsigned AppX Installation
Flags PowerShell usage of Add-AppxPackage/Add-AppPackage with -AllowUnsigned to install unsigned AppX packages.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium123Free2023-01-31Windows PowerShell Base64-Encoded WMI Class Invocation
Flags PowerShell command lines containing Base64 fragments indicative of WMI class usage (e.g., ShadowCopy, ScheduledJob) on Windows.
Christian Burkard (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-01-30Windows Registry: Monitor PendingFileRenameOperations changes from suspicious images
Alerts on registry tampering of PendingFileRenameOperations by processes running from suspicious image paths.
frack113, Huntrule TeamWindowsregistry_setMedium71Free2023-01-27Windows WMIC System Information Discovery via WMIC.EXE Recon
Flags WMIC.EXE executions running system info queries for OS and disk details.
TropChaud, Huntrule TeamWindowsprocess_creationMedium272Free2023-01-26Windows: Suspicious Child Process Spawned by VsCode code.exe
Alerts when code.exe spawns suspicious binaries, script hosts, or command-line activity that matches common execution patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium141Free2023-01-26Windows WSL Process Spawning Uncommon Child Executables
Alerts when wsl.exe or wslhost.exe spawns suspicious child binaries from common temp/public/user directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2023-01-23Windows PowerShell Module Execution Matches Known Offensive PoshModule Script Names
Alerts on Windows PowerShell module executions where the script context matches known offensive PowerShell script/module names.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_moduleHigh415Free2023-01-23