Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,443 rules
Windows UEFI Persistence: Detect wpbbin.exe Execution
Alerts on execution of C:\Windows\System32\wpbbin.exe, a potential indicator of UEFI persistence on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-07-18Windows UEFI Persistence Indicator: Creation of C:\Windows\System32\wpbbin.exe
Flags creation of C:\Windows\System32\wpbbin.exe, a potential UEFI persistence artifact.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh452Free2022-07-18Windows Registry Fax Device Provider ImageName changed to load external DLL
Alerts when Fax Device Providers\ImageName registry values change in a way consistent with DLL-loading persistence.
frack113, Huntrule TeamWindowsregistry_setHigh103Free2022-07-17Windows Registry: User Account Changed for FAX Service
Flags registry changes that alter the FAX service’s associated user account on Windows.
frack113, Huntrule TeamWindowsregistry_setHigh245Free2022-07-17Windows UAC Bypass via iscsicpl.exe DLL Search Order Hijacking (iscsiexe.dll)
Detects iscsicpl.exe loading iscsiexe.dll from outside C:\Windows, consistent with UAC bypass DLL hijacking.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh412Free2022-07-17Windows System Process Loads DLL from Suspicious or Permissive Paths
Alerts when a Windows system process loads a DLL from permissive or suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium151Free2022-07-17Windows Process Creation: NTVDM (ntvdm.exe/csrstub.exe) Start for 16-bit App Compatibility
Flags creation of NTVDM-related processes (ntvdm.exe or csrstub.exe) used to run legacy 16-bit/DOS applications on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium153Free2022-07-16Windows Process Initiated Connections to Ngrok Domains
Alerts when a Windows process initiates an outbound connection to ngrok domain hostnames, which may indicate staging or C2 activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh152Free2022-07-16Windows Scheduled Task Creation Triggered Once at 00:00 Using Scripted Commands
Alerts on suspicious schtasks.exe task creation for a one-time 00:00 run with embedded script/command execution strings.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-07-15Sysmon DNS Query for anonfiles.com Domain
Flags Windows Sysmon DNS queries referencing anonfiles.com to support detection of suspicious data staging.
pH-T (Nextron Systems), Huntrule TeamWindowsdns_queryHigh101Free2022-07-15Windows Suspicious Service Creation via sc.exe or PowerShell New-Service with Abnormal Binary Paths
Flags service creation commands (sc.exe/New-Service) when the specified binary path includes suspicious directories or script/loader utilities.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2022-07-14Windows: Detect sc.exe Creating Kernel Driver Services
Flags sc.exe service creation where the command-line specifies a kernel driver type and binPath.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium264Free2022-07-14MSSQL sp_procoption Startup Execution Set/Clear via Application Log EventID 33205
Alerts on MSSQL sp_procoption being set or cleared for automatic startup execution via EXEC (EventID 33205).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh91Free2022-07-13Windows/MSSQL: Detect ALTER SERVER AUDIT or DROP SERVER AUDIT executions
Alerts on MSSQL ALTER/DROP SERVER AUDIT statements that disable or delete server audit coverage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh386Free2022-07-13Windows MSSQL: Add Member to sysadmin Server Role (EventID 33205)
Alerts on MSSQL EventID 33205 when an ALTER SERVER ROLE command adds a member to the sysadmin role.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh133Free2022-07-13