Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Headless Chromium Browser Execution via --headless
Alerts on headless Chromium-based browser launches on Windows using the "--headless" command-line flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-09-12Windows Process Creation: wmic.exe call terminate Attempt
Alerts on wmic.exe being executed with “call terminate”, indicating an attempt to terminate a process on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2023-09-11Windows Process Creation: Execution of Renamed curl.exe via PE Metadata
Alerts on Windows process launches whose PE metadata matches curl.exe even when the executable image is renamed.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium469Free2023-09-11Windows Chromium Headless Execution with Mockbin/Mocky URL
Alerts when a Chromium-based browser runs headless on Windows with a mockbin-like URL in the command line.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2023-09-11Windows Suspicious Creation of .dmp/.hdmp Files by Shell or Script Hosts
Alerts on .dmp/.dump/.hdmp file creation by common Windows shells and scripting engines.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium172Free2023-09-07Windows Registry: Enabled TLS 1.0 or TLS 1.1 via SCHANNEL Protocols Enabled=1
Flags registry changes that set SCHANNEL TLS 1.0/1.1 Enabled to 1 on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium243Free2023-09-05Windows Registry ZoneMap ProtocolDefaults Downgraded to My Computer for HTTP/HTTPS
Flags IE/Windows ZoneMap changes setting HTTP/HTTPS ProtocolDefaults DWORD 0x00000000 to the My Computer zone.
Nasreddine Bencherchali (Nextron Systems), Michael Haag (idea), Huntrule TeamWindowsregistry_setHigh301Free2023-09-05Suspicious CommandLine Parameters for Electron Apps on Windows
Alerts on Electron app execution with command-line flags consistent with subprocess and renderer/utility launching behavior.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2023-09-05Windows Process Creation: IE ZoneMap ProtocolDefaults downgraded to My Computer for HTTP/HTTPS
Flags Windows command lines that set IE ZoneMap ProtocolDefaults for HTTP to the My Computer (zone 0) trust level.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh268Free2023-09-05Windows: Detect VMMap loading a signed dbghelp.dll from C:\Debuggers\
Alerts on vmmap.exe/vmmap64.exe loading a signed dbghelp.dll from C:\Debuggers, consistent with potential DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium133Free2023-09-05Windows: Zone.Identifier Alternate Data Stream Deleted by Uncommon Application
Alert on deletion of the Zone.Identifier ADS by an uncommon process on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium91Free2023-09-04Suspicious Child Process Spawned by WinRAR.exe on Windows
Alerts when WinRAR.exe launches command, scripting, or proxy execution binaries on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-08-31Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh193Free2023-08-29Windows Process Watch: PythonFunctionWarnings Disabled via Excel Security Registry Setting
Flags Excel-related process command lines that disable Python function execution warnings via PythonFunctionWarnings=0.
"@Kostastsale, Huntrule Team"Windowsprocess_creationHigh411Free2023-08-22Windows Process Execution Triggered from WebDAV LNK Paths
Alerts on explorer.exe launching cmd/cscript/mshta/powershell/wscript/pwsh when the command line references a WebDAV \DavWWWRoot\ LNK path.
Micah Babinski, Huntrule TeamWindowsprocess_creationMedium123Free2023-08-21