Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows Registry AMSI COM Server Hijacking via InProcServer32 CLSID Modification
Alerts on registry changes that alter an AMSI COM CLSID InProcServer32 entry to break AMSI loading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh438Free2023-01-04Windows PowerShell Keylogger Function Reference in Script Block Logging
Alerts on PowerShell script blocks containing keyboard IsKeyDown references associated with potential keystroke capture.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium111Free2023-01-04Windows Process Creation: Suspicious Git Clone Command With Vulnerability Keywords
Flags Windows git clone commands that include exploit/vulnerability-style keywords in the process command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium469Free2023-01-03Windows Registry EventLog Service File Location Tampering
Flags registry modifications that change the EventLog service’s configured log file location on Windows.
D3F7A5105, Huntrule TeamWindowsregistry_setHigh161Free2023-01-02Windows Ruby Inline Code Execution via Ruby.exe -e Flag
Flags Windows executions of ruby.exe that include the inline code flag (-e) for direct command-line Ruby code.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium183Free2023-01-02Windows Process Creation: Python Executed with the -c Inline Code Flag
Flags Windows executions of python.exe with -c inline code, excluding common installer/baseline and VS Code contexts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium171Free2023-01-02Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Alerts on Windows process launches whose command line includes well-known malicious PowerShell commandlet names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2023-01-02Windows: Inline PHP execution via php.exe -r flag
Flags Windows process executions of php.exe with the inline "-r" code execution flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2023-01-02Windows Process Creation: Perl Inline Code Execution via -e/-E
Flags command-line usage of perl.exe with inline execution (-e) on Windows process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium205Free2023-01-02Windows EVTX File Creation in Non-Standard Locations
Flags creation of .evtx files outside typical Windows event log directories to support event log evasion or export.
D3F7A5105, Huntrule TeamWindowsfile_eventMedium3510Free2023-01-02Windows Process Creation: Uncommon Child Processes Spawned by DefaultPack.EXE
Alerts when DefaultPack.exe spawns an uncommon child process, indicating potential proxy execution on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium436Free2022-12-31Windows Image Load: coregen.exe Potential DLL Sideloading
Identifies potential DLL sideloading when coregen.exe loads DLLs outside expected system and Silverlight locations.
frack113, Huntrule TeamWindowsimage_loadMedium418Free2022-12-31Windows SharpLDAPmonitor HackTool Execution via Image Name and Credential/DC Flags
Flags SharpLDAPmonitor execution on Windows with LDAP-related command-line parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2022-12-30Windows: ssh.exe Used as Proxy/Local Command Launcher via ProxyCommand and LocalCommand
Detects Windows executions of ssh.exe that use ProxyCommand and PermitLocalCommand/LocalCommand to launch proxied or local commands.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium259Free2022-12-29Windows: PowerShell Enable-WindowsOptionalFeature Enables Suspicious Optional Features
Alerts on PowerShell Enable-WindowsOptionalFeature used with -Online to enable listed optional features.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium495Free2022-12-29