Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,451 rules
Windows PowerShell: GPO ScriptBlock Modifying Group Policy and SmartScreen Settings
Alerts on PowerShell ScriptBlock content referencing Group Policy policy keys and specific security policy value names.
frack113, Huntrule TeamWindowsps_scriptMedium259Free2022-08-19Windows Process Execution of HandleKatz LSASS Dumper (loader.exe)
Flags HandleKatz-style loader.exe executions that dump LSASS into obfuscated .obf files using --pid and --outfile.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2022-08-18Windows driver load of HackSys Extreme Vulnerable Driver (HEVD.sys) via image hash
Flags Windows systems when HEVD driver \HEVD.sys is loaded with known IMPHASH values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh2110Free2022-08-18Windows Malicious Driver Load by Known Hashes
Alerts on Windows driver loads matching known malicious driver hashes (MD5/SHA1/SHA256/IMPHASH).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh374Free2022-08-18Windows Executable Connections to Dead Drop Resolver Domains Excluding Common Browsers
Flags non-browser Windows executables making outbound connections to known dead-drop resolver domain patterns.
Sorina Ionescu, X__Junior (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh403Free2022-08-17Windows DLL sideloading via third-party application directories (ImageLoad event)
Flags Windows ImageLoad events for specific DLL sideloading candidates tied to Lenovo and Toshiba software.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium101Free2022-08-17Windows: Detect Microsoft Office DLL sideloading via ImageLoad of outllib.dll from nonstandard path
Alerts on outllib.dll loads from non-standard locations rather than typical Microsoft Office directories.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadHigh113Free2022-08-17Windows Chrome Frame Helper DLL Sideloading via Image Load
Alerts when chrome_frame_helper.dll loads from an unexpected location on Windows, indicating possible DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium3810Free2022-08-17Windows DLL Sideloading Using Antivirus/Vendor DLLs Based on Loaded Image Names
Alerts on suspicious DLL loads matching known antivirus/security component DLL names when not from expected vendor paths.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium323Free2022-08-17Sysmon FileBlockExecutable event: blocked executable execution attempts on Windows
Alerts when Sysmon blocks an attempted executable execution due to FileBlockExecutable policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssysmonHigh4610Free2022-08-16PowerShell Write-EventLog with -RawData Flag
Alerts when PowerShell script blocks call Write-EventLog using the -RawData flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium133Free2022-08-16Windows Process Creation: mshtml.dll RunHTMLApplication Execution via Protocol Handlers
Alerts on Windows command lines invoking mshtml.dll RunHTMLApplication (via #135) with path traversal markers.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Josh Nickels, frack113, Zaw Min Htun (ZETA), Huntrule TeamWindowsprocess_creationHigh251Free2022-08-14Windows Firewall rule deleted via netsh.exe command line
Flags netsh.exe executions that contain Windows Firewall rule deletion commands.
frack113, Huntrule TeamWindowsprocess_creationMedium113Free2022-08-14Windows DLL Sideloading: System DLL Names Loaded from Non-Standard Paths (ImageLoad)
Alerts when Windows image loads DLL names typically found in system locations, excluding common benign paths to reduce false positives.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh1910Free2022-08-14Windows rundll32 Loading Renamed comsvcs.dll via DLL Image Load
Flags rundll32.exe loading a renamed comsvcs.dll module consistent with process memory dumping behavior on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2022-08-14