Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows sdbinst.exe Installing Shim Database with Uncommon Extension
Flags sdbinst.exe process executions consistent with installing shim databases using uncommon .sdb command-line patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium464Free2023-08-01Windows VMMap Loading Unsigned dbghelp.dll from C:\Debuggers\dbghelp.dll
Alerts when VMMap loads an unsigned dbghelp.dll from C:\Debuggers, suggesting DLL sideloading on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh122Free2023-07-28Windows CreateRemoteThread in mstsc.exe From Suspicious Source Paths
Alerts when mstsc.exe creates remote threads from processes running out of common suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_remote_threadHigh249Free2023-07-28Windows: Alert on wget.exe downloading files from an IP with output flags
Flags Windows wget.exe usage to download HTTP URLs from IPs and write outputs to script/binary extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3510Free2023-07-27Windows: curl.exe Local File Read via file:/// Command Line
Flags curl.exe runs that include file:/// to access local files on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-07-27Windows: Curl.exe Insecure Proxy/DOH Transfer Flags
Flags curl.exe with --proxy-insecure and/or --doh-insecure during Windows process execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-07-27Suspicious curl.exe File Downloads From Direct IP Addresses on Windows
Alerts on Windows curl.exe commands downloading from an IP address with HTTP/S and suspect file extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2023-07-27Windows Process Execution: curl.exe with Custom User-Agent Header
Flags Windows executions of curl.exe that include a User-Agent header in the command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-07-27Windows Process Execution: curl.exe Saving Cookies via -c / --cookie-jar
Flags curl.exe commands that save cookie jar data using -c/--cookie-jar on Windows process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium341Free2023-07-27Windows Terminal settings.json modified by uncommon process
Alerts on Windows Terminal settings.json changes made by an uncommon command-line or script host process.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium92Free2023-07-22Windows Sysmon FileExecutableDetected (Event ID 29) Alerts on New Executable Files
Alerts on any Sysmon Event ID 29 indicating a new monitored executable file was created on Windows.
frack113, Huntrule TeamWindowssysmonMedium448Free2023-07-20Sysmon FileBlockShredding Policy Violations (Event ID 28) on Windows
Alerts on Sysmon Event ID 28 when file shredding is blocked by the configured shredding policy on Windows.
frack113, Huntrule TeamWindowssysmonHigh387Free2023-07-20Windows Process Creation: schtasks.exe Creating Scheduled Task Launching Registry-Stored PowerShell Payload
Flags schtasks.exe /Create scheduled tasks that launch PowerShell decoding and executing a base64 payload retrieved from Windows Registry.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-07-18Windows netsh.exe Advanced Firewall Rule Set Modification
Flags netsh.exe command lines that invoke advfirewall firewall set to modify existing Windows firewall rule properties.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2023-07-18Windows Process Creation: One-liner cmd.exe CommandLine with ping and copy
Alerts when cmd.exe runs a one-liner that includes both ping and copy with expected options.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium103Free2023-07-18