Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,449 rules
Windows PsExec Named Pipe Creation from Suspicious Paths (PSEXESVC)
Alerts on PsExec pipe \PSEXESVC creation when the executing image path is in public/temp/desktop/downloads locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdMedium322Free2022-08-04Windows CLI usage of obfuscated IP address patterns in ping/arp commands
Alerts when ping or arp command lines include obfuscated/encoded IP address indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-08-03Windows Process Creation: Obfuscated IP Address in Download Command URLs
Alerts on Windows download commands that include obfuscated/encoded IP addresses in the URL.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-08-03Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdCritical407Free2022-08-03Windows Security Mitigations: Unsigned DLL Blocked from User-Writable Paths
Alerts on blocked unsigned DLL loads targeting public, downloads, desktop, or temp directories in Windows Security Mitigations logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurity-mitigationsHigh132Free2022-08-03Windows Security: DiagTrackEoP POC Default UserName Login Attempt (LogonType 9)
Alerts on Windows 4624 LogonType 9 events targeting a known DiagTrackEoP default username.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityCritical130Free2022-08-03Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2410Free2022-08-02Windows PowerShell Invoke-WebRequest Download to Suspicious Paths
Alert when PowerShell uses Invoke-WebRequest/aliases with download flags and targets suspicious file locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2022-08-02Windows: Detect VMwareXferlogs.exe Executed from Non-default Path
Alert on VMwareXferlogs.exe launching from an unexpected directory, a potential DLL sideloading technique on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh125Free2022-08-02Windows mpclient.dll Sideloading via MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when mpclient.dll is loaded by MpCmdRun.exe or NisSrv.exe outside known Windows Defender directories.
Bhabesh Raj, Huntrule TeamWindowsimage_loadHigh82Free2022-08-02Windows: Potential DLL sideloading via VMwareXferlogs loading glib-2.0.dll from non-standard path
Alerts on VMwareXferlogs.exe loading glib-2.0.dll from outside the default VMware directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh2810Free2022-08-02Windows Code Integrity blocks unsigned DLL loads into MpCmdRun.exe and NisSrv.exe
Flags security-mitigations events where MpCmdRun or NisSrv are prevented from loading unsigned DLLs.
Bhabesh Raj, Huntrule TeamWindowssecurity-mitigationsHigh91Free2022-08-02Windows Registry Set to Disable Windows Defender Components
Flags registry changes that turn off Windows Defender protections via Defender and Security Center policy keys.
AlertIQ, Ján Trenčanský, frack113, Nasreddine Bencherchali, Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setHigh112Free2022-08-01Windows Registry: Attachment Manager policy tampering via Attachments settings values
Detects registry changes to Windows Attachment Manager policy values that can disable or alter download safety controls.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh133Free2022-08-01Windows Registry Tampering: Attachment Manager Associations Default File Type Risk and LowRiskFileTypes
Flags Windows registry changes to Attachment Manager associations that set DefaultFileTypeRisk and modify LowRiskFileTypes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh179Free2022-08-01