Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,442 rules
Windows File Events: Flag Files With Double Extensions (e.g., .docx.exe)
Alerts on Windows filenames that look like double extensions, including .rar.exe/.zip.exe masquerading patterns.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsfile_eventHigh193Free2022-06-19Windows: msdt.exe Loads sdiageng.dll via Image Load Events
Flags msdt.exe image-load events that load sdiageng.dll, a behavior commonly associated with DLL side-loading abuse.
Greg (rule), Huntrule TeamWindowsimage_loadHigh179Free2022-06-17Windows Process Creation: Sysinternals PsService (PsService*.exe) Execution
Alerts on execution of Sysinternals PsService (PsService*.exe) on Windows, which can support service discovery and tampering.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium4410Free2022-06-16Windows OpenConsole LOLBIN Execution via Process Creation
Alerts when OpenConsole.exe runs (outside a specific Windows Terminal path), potentially used to bypass application whitelisting.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium319Free2022-06-16Windows Registry: Enable ScriptedDiagnostics TurnOffCheck DWORD via Policies
Flags registry policy enabling ScriptedDiagnostics TurnOffCheck (DWORD 0x00000001) on Windows.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamWindowsregistry_setMedium133Free2022-06-15Windows: Execution of Pcalua.exe with -a Argument
Flags Pcalua.exe executions containing " -a" that may indicate indirect command execution on Windows.
Nasreddine Bencherchali (Nextron Systems), E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationMedium392Free2022-06-14Windows forfiles.exe Execution with /c Flag Command Proxying
Flags forfiles.exe executions that include the /c flag, indicating potential indirect command execution.
Tim Rauch, Elastic, E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationMedium121Free2022-06-14Windows conhost.exe Path Traversal in Process Command Line
Detects Windows conhost.exe command lines containing '/../../' path traversal indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-06-14Windows msdt.exe execution using PCWDiagnostic.xml answer file
Alerts on msdt.exe launched with PCWDiagnostic.xml and an answer-file argument, excluding cases from pcwrun.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2910Free2022-06-13Windows: Indirect execution of pcwrun.exe using path traversal-style command line content
Detects pcwrun.exe spawning with '../' in the command line, indicating potential indirect execution abuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-06-13Windows Registry Custom File Open Handler Executes PowerShell
Alerts when a registry shell open handler is created to run PowerShell with -command.
CD_R0M_, Huntrule TeamWindowsregistry_setHigh112Free2022-06-11Windows Process: Notepad++ GUP (GUP.exe) Download Execution via -unzipTo and URL
Detects Notepad++ GUP.exe downloading over HTTP initiated by a non-Notepad++ parent process.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh256Free2022-06-10Windows: GUP Utility Spawns Commands from Explorer via Notepad++ Updater
Flags Notepad++ updater-launched GUP activity that causes explorer.exe to execute with notepad++ in the command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium368Free2022-06-10Windows: New Notepad++ plugins DLL written outside gup.exe
Alerts on creation of Notepad++ plugin DLLs by a process other than gup.exe, suggesting possible persistence via custom plugins.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium277Free2022-06-10Windows BITS Client Job Downloads From Uncommon Remote TLDs
Alerts on BITS transfers (EventID 16403) to remote domains with uncommon or suspicious TLD patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientMedium121Free2022-06-10