Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: RjvPlatform.dll loaded by SystemResetPlatform.exe from $SysReset path
Alerts on SystemResetPlatform.exe loading RjvPlatform.dll from the $SysReset Framework Stack path on Windows.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium2210Free2023-06-09Windows DLL Sideloading Suspicion via edputil.dll Image Load
Alerts on edputil.dll image loads occurring outside standard Windows system directories, suggesting possible DLL side-loading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh112Free2023-06-09Windows DLL Sideloading Indicators: 7za.dll Loaded from Non-Program Files Paths
Alerts when a process loads 7za.dll from a non-Program Files path, indicating potential DLL sideloading.
X__Junior, Huntrule TeamWindowsimage_loadLow186Free2023-06-09Windows ClickOnce Loads Unsigned or Expired Signed Modules from User Apps Path
Alerts when a ClickOnce app loads a module from Apps\2.0 that is unsigned or has an expired signature.
"@SerkinValery, Huntrule Team"Windowsimage_loadMedium258Free2023-06-08Windows Registry COM InProcServer32 Hijack via PSFactory CLSID Default Value
Detects suspicious modifications to a PSFactory COM InProcServer32 (Default) registry value that may enable COM-based persistence.
BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk, Huntrule TeamWindowsregistry_setHigh452Free2023-06-07Windows Code Integrity: Kernel Module Loaded Without WHQL Requirements (Event 3082/3083)
Alerts when Code Integrity logs show loaded kernel modules failing WHQL compliance (Event 3082/3083), excluding selected VMware drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh82Free2023-06-06Windows Code Integrity Operational: Unsigned Image Loaded
Alerts on Windows Code Integrity detecting that an unsigned image was loaded (Event ID 3037).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh111Free2023-06-06Windows Code Integrity Unsigned Kernel Module Loaded (Event ID 3001)
Alerts on Windows Code Integrity reporting an unsigned kernel module load via Event ID 3001.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh289Free2023-06-06Windows Code Integrity: Revoked Signed Image Loaded (Event 3032/3035)
Alerts on Code Integrity events showing a revoked signed image was loaded, including debugger-allowed cases.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh143Free2023-06-06Windows Code Integrity blocks image load when signing certificate is revoked (Event ID 3036)
Alerts on Windows Code Integrity Event ID 3036 when image loads are blocked because the signing certificate is revoked.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh122Free2023-06-06Windows Code Integrity: Revoked Kernel Driver Loaded (Event 3021/3022)
Alerts when Windows Code Integrity reports a revoked kernel driver/module loaded (including debugger-allowed cases) via Event IDs 3021/3022.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh179Free2023-06-06Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Flags Code Integrity Operational events where Windows blocks loading a revoked (untrusted) driver certificate.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh147Free2023-06-06Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
Alerts on Windows Code Integrity Event ID 3104 when a disallowed file is blocked for protected processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh113Free2023-06-06Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript
Alerts on suspicious renamed AutoIt2/AutoIt3 execution based on command-line parameters plus known hashes and original file names.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2023-06-04Windows DLL Sideloading via SmadHook32c.dll and SmadHook64c.dll Loads
Alerts on non-standard loads of SmadHook32c.dll/SmadHook64c.dll on Windows, consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh181Free2023-06-01