Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,452 rules
Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh264Free2022-08-25Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2022-08-24Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Flags Sysinternals-related registry EULA acceptance writes tied to PsExec/ProcDump/Process Explorer and other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium70Free2022-08-24Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Flags registry writes to EulaAccepted for Sysinternals-named targets when executed by non-matching image filenames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh70Free2022-08-24Windows File Changes to Microsoft.VSCode_profile.ps1 via PowerShell Profile
Detects creation or modification of Microsoft.VSCode_profile.ps1 based on Windows file events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium91Free2022-08-24Windows msdt.exe Creating Files in Common Startup and Public Directories
Alerts when msdt.exe writes files to high-suspicion directories that may indicate persistence after exploitation.
Vadim Varganov, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-08-24Windows Named Pipe Stream Created with Known Hack Tool IMPHASHs
Alerts on Windows named file stream creation events whose IMPHASH matches common hack-tool binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh122Free2022-08-24Windows Suspicious File Download Streams From File/Paste Hosting Domains With Script Extensions
Alert on Windows file stream hash creation involving downloads from paste/file-sharing domains targeting .bat/.cmd/.ps1 content indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashMedium171Free2022-08-24Windows CreateStreamHash: Suspicious Downloads From File Sharing and Paste Websites
Identifies Windows stream-hash events tied to downloads from file-sharing/paste domains with Zone-tagged payload extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh60Free2022-08-24Windows Registry: New NetworkProvider service keys indicative of credential dumping
Alerts on registry additions/changes to NetworkProvider service entries that may be used to dump clear-text credentials.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium247Free2022-08-23Windows Process Creation Using the Sysnative Directory Path
Alerts on process executions referencing \Windows\Sysnative, excluding common ngen.exe and a known XAMPP bat launcher.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2022-08-23Windows Process Creation: Suspicious CLI NetworkProvider Addition for Credential Dumping
Alerts on Windows CLI executions that reference services\... and NetworkProvider, a pattern consistent with credential dumping via provider changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-08-23Windows cmd.exe Command-Line Anomaly: Missing Spaces Around /c /k /r
Flags cmd.exe invocations with suspicious missing spaces around /c, /k, or /r based on process creation CommandLine patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-08-23Windows Registry Persistence Risk: TypedPaths Key Modified by Non-Explorer Processes
Alerts on changes to Explorer TypedPaths registry entries from processes other than explorer.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh152Free2022-08-22Windows Rundll32 Masquerading: DllRegisterServer CommandLine Not Using rundll32.exe
Alerts when 'DllRegisterServer' appears in the command line while the executing image is not rundll32.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh441Free2022-08-22