Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry IME File Value Used from Suspicious Paths
Alerts on Windows keyboard layout "Ime File" registry entries pointing to suspicious writable directory paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2023-11-21Windows Registry: Uncommon IME File Value in Keyboard Layouts Path
Alerts on Control\Keyboard Layouts\ registry values named "Ime File" that reference non-.ime extensions.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setHigh228Free2023-11-21Windows Network Connections to Visual Studio Code Tunnels Domain
Alerts on initiated network connections to .tunnels.api.visualstudio.com from a Windows process.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium112Free2023-11-20Windows Network Connections to *.devtunnels.ms
Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium101Free2023-11-20Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
Alerts when excel.exe spawns foxprow.exe, schdplus.exe, or winproj.exe, consistent with suspicious Excel DCOM automation activity.
Aaron Stratton, Huntrule TeamWindowsprocess_creationHigh143Free2023-11-13Windows: Command-Line Use of ms-appinstaller Protocol Handler for File Downloads
Alerts on Windows command lines invoking ms-appinstaller with an http source, indicating potential remote file download behavior.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium252Free2023-11-09Windows msxsl.exe Execution with HTTP Keyword in Command Line
Flags execution of msxsl.exe when the command line includes an HTTP URL indicator.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh70Free2023-11-09Windows: File Download via msedge_proxy.exe Using HTTP/HTTPS URLs
Flags msedge_proxy.exe executions that include HTTP/HTTPS URLs, consistent with arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium168Free2023-11-09Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS
Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh383Free2023-11-09Windows Registry: Disabling Antivirus Filter Driver on Dev Drive via FltmgrDevDriveAllowAntivirusFilter
Detects registry changes disabling antivirus minifilter inspection on a Dev Drive by setting the allow setting to 0x0.
"@kostastsale, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsregistry_setHigh333Free2023-11-05Windows Registry: AllowAnonymousCallback Enabled for Anonymous Remote Connection
Alerts on setting AllowAnonymousCallback to 0x00000001 in the CIMOM key, enabling anonymous remote connections.
X__Junior (Nextron Systems), Huntrule TeamWindowsregistry_setMedium102Free2023-11-03Windows image load and execution of unsigned Thor scanner (thor.exe/thor64.exe)
Alerts on thor.exe/thor64.exe image loads on Windows where the Authenticode signature is missing or not from Nextron Systems.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh469Free2023-10-29Windows Process Creation: VS Code Tunnel (code-tunnel) Installed as a Service
Alerts on Windows process command lines consistent with installing VS Code tunnel (code-tunnel) as a service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2023-10-25Windows: VS Code Tunnel Launching PowerShell or WSL/Bash Shell
Flags VS Code tunnel (node.exe) spawning PowerShell, WSL, or bash shell processes on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2023-10-25Windows Process Creation: Visual Studio Code Tunnel (.exe tunnel) Execution
Flags cmd.exe-launched Visual Studio Code tunnel processes with expected tunnel and license-accept arguments on Windows.
Nasreddine Bencherchali (Nextron Systems), citron_ninja, Huntrule TeamWindowsprocess_creationMedium60Free2023-10-25