Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,467 rules
Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-01-18Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Alerts on Windows Defender Firewall configurations where all rules are deleted (Event 2033/2059), signaling potential defense impairment.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asHigh163Free2023-01-17PowerShell Data Exfiltration Using Audio File (WAV BinaryWriter) on Windows
Alerts on PowerShell script blocks that appear to write data into an audio (WAV) file for potential exfiltration.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium142Free2023-01-16Windows DNS Client: DNS queries containing "ufile.io"
Alerts on Windows DNS Client queries where the queried name includes "ufile.io".
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientLow173Free2023-01-16Windows DNS Client: MEGA userstorage subdomain DNS query (EventID 3008)
Detects Windows DNS client queries for MEGA userstorage subdomains by matching the query name string.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientMedium122Free2023-01-16Windows DNS Client: Cobalt Strike DNS Beaconing Patterns via Suspicious Query Names
Alerts when Windows DNS client logs show Event ID 3008 DNS queries matching Cobalt Strike beacon patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientCritical4410Free2023-01-16Windows DNS Client: DNS query for anonfiles.com domain
Alerts when Windows DNS client logs show a DNS query containing .anonfiles.com.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientHigh171Free2023-01-16Windows AppX Packaging: Execute AppX with Suspicious Digital Signature Certificate
Alerts when AppX package execution/signature subject matches a known suspicious certificate in Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxpackaging-omMedium122Free2023-01-16Windows AppX Execution of Sysinternals Tools (procdump/psloglist/psexec/livekd/ADExplorer)
Flags execution of common Sysinternals binaries when launched through the Windows AppX runtime.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappmodel-runtimeLow316Free2023-01-16Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
Flags registry writes that reference an Excel XLL add-in via a '/R ' command under Excel Options.
frack113, Huntrule TeamWindowsregistry_setHigh378Free2023-01-15Windows Registry: DisableRestrictedAdmin Value Tampering to Change Restricted Admin Mode
Flags registry modifications to DisableRestrictedAdmin that change Restricted Admin mode settings.
frack113, Huntrule TeamWindowsregistry_setHigh142Free2023-01-13Windows Process Creation: Registry Tampering of DisableRestrictedAdmin in Lsa Key
Alerts when a process command line references LSA DisableRestrictedAdmin to change RestrictedAdmin behavior via the registry.
frack113, Huntrule TeamWindowsprocess_creationHigh417Free2023-01-13Windows Task Scheduler: Detects Scheduled Task Deletion or Disabling (Task Deleted/Disabled)
Alert on deletion or disabling of targeted Windows scheduled tasks tied to system, security, and update components.
frack113, Huntrule TeamWindowstaskschedulerHigh244Free2023-01-13Windows LSA event: Standard user SID in privileged AD groups (EventID 300)
Alerts when LSA Event 300 shows a standard user interacting with high-privileged group SIDs, excluding common domain admin patterns.
frack113, Huntrule TeamWindowslsa-serverMedium142Free2023-01-13Windows Registry change enabling developer features for sideloading and untrusted app installs
Alerts on registry writes that enable Windows developer feature policies allowing sideloading of untrusted apps.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2023-01-12