Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows PowerShell Script Modifies File Permissions with Set-Acl
Flags PowerShell scripts that call Set-Acl to change ACL permissions on a specified path.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow80Free2023-07-18Windows PowerShell WMI Win32_NTEventlogFile Calls with Event Log Tampering Methods
Flags PowerShell calling Win32_NTEventlogFile WMI methods commonly used to clear, delete, backup, or alter Windows event logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2023-07-13Suspicious PowerShell WMI Win32_NTEventlogFile Usage (Event Log Tampering)
Detects PowerShell scripts calling Win32_NTEventlogFile methods associated with event log deletion, backup, renaming, or permission changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium163Free2023-07-13Windows DLL Sideloading: CCleanerReactivator.dll Loaded from CCleaner Directories
Identifies potential CCleanerReactivator.dll DLL sideloading when loaded by CCleanerReactivator.exe outside expected CCleaner paths.
X__Junior, Huntrule TeamWindowsimage_loadMedium228Free2023-07-13Windows DLL Sideloading via CCleanerDU.dll ImageLoad from CCleaner Folder
Alerts when CCleanerDU.dll is loaded, but the loading image is not CCleaner executables in standard install paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium142Free2023-07-13Windows Process Creation From Fake Recycle.Bin Directories
Alerts on Windows processes launched from fake RECYCLER.BIN / RECYCLERS.BIN folder paths often used for stealth.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh329Free2023-07-12Windows: wordpad.exe Initiated Network Connections on Uncommon Ports
Alerts when wordpad.exe initiates outbound connections on destination ports outside common C2-related ports.
X__Junior (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium141Free2023-07-12Windows Office Apps Initiating Network Connections to Non-Common Ports
Alerts on network connections initiated by Windows Office apps to destination ports not in the common port set.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium427Free2023-07-12Windows: Suspicious File Creation in Fake RECYCLER.BIN Staging Folders
Alerts on Windows file writes involving RECYCLERS.BIN\ or RECYCLER.BIN\ paths often used for staging.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh408Free2023-07-12Windows DLL Sideloading via Abusable DLLs Loaded from Suspicious Locations
Flags Windows module loads of specific abusable DLL names from public, temp, or user folders consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh445Free2023-07-11Windows: Recon command output piped to findstr.exe
Alerts on Windows command lines running recon commands whose output is filtered with findstr.exe.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium81Free2023-07-06Windows process creation: WerFault.exe executed with -pr flag
Alerts when WerFault.exe is launched with the -pr argument, potentially indicating ReflectDebugger-based execution.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-06-30Windows PowerShell Decryption-Like Activity Involving .LNK File Processing
Identifies PowerShell runs that enumerate and process *.lnk content using byte-level reads/writes consistent with decryption staging.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2023-06-30Windows Process Execution of curl.exe with --insecure Flag
Flags curl.exe launched with --insecure/-k to disable TLS certificate verification.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2023-06-30Windows Registry: Uncommon Microsoft Office Trusted Location Path Added
Alerts on registry changes adding non-standard Microsoft Office Trusted Location paths that could undermine macro security.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2023-06-21