Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Odbcconf.exe used to register a DLL via REGSVR
Flags odbcconf.exe executions using REGSVR to register a DLL, a regsvr32-equivalent technique often abused by attackers.
Kirill Kiryanov, Beyu Denis, Daniil Yugoslavskiy, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-05-22Windows Process Execution: odbcconf.exe with DLL in Suspicious Path
Flags odbcconf.exe process launches when the command line references DLL-related paths in suspicious Windows locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2023-05-22Windows: Detect Odbcconf.exe INSTALLDRIVER DLL Installation via Process Command Line
Alerts when odbcconf.exe is run with INSTALLDRIVER and a .dll, indicating potential malicious ODBC driver DLL installation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-05-22Windows Suspicious Non-Browser Network Traffic to api.telegram.org
Alerts on Windows network connections to api.telegram.org by processes other than common web browsers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium131Free2023-05-19Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters
Flags Windows Event 4661 activity indicating password policy enumeration (ReadPasswordParameters on Security Account Manager).
Zach Mathis, Huntrule TeamWindowssecurityMedium167Free2023-05-19Windows WerFault ReflectDebugger Registry Key Value Targeting
Flags registry set events targeting WerFault ReflectDebugger under Windows Error Reporting Hangs for potential persistence abuse.
X__Junior, Huntrule TeamWindowsregistry_setHigh141Free2023-05-18PowerShell Certificate Export Cmdlets in Windows Process Creation
Flags PowerShell command lines invoking certificate export cmdlets (Export-PfxCertificate/Export-Certificate) on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium428Free2023-05-18Windows WWlib.DLL sideloading via Office process loading behavior
Alert on Windows image-load events where winword-associated processes load wwlib.dll outside expected Office paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium203Free2023-05-18Windows CreateStreamHash: Suspicious Embedded File Download Indicators via .zip TLD
Flags Windows downloads indicating .zip/ plus ':Zone' in target filenames for risky executable or script extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh162Free2023-05-18Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments
Flags rundll32.exe launches with command-line ordinal obfuscation patterns.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2023-05-17Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2023-05-17Windows Process Creation: cloudflared Tunnel Execution with Config and Credentials Flags
Alerts on Windows processes running cloudflared tunnels with config and token/credential flags.
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium361Free2023-05-17Windows: Detect cloudflared tunnel cleanup command execution
Flags Windows executions of cloudflared with tunnel cleanup and connector/config parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium332Free2023-05-17Windows Registry: Internet Explorer DisableFirstRunCustomize Set via Explorer or ie4uinit
Alerts on Windows registry writes to Internet Explorer DisableFirstRunCustomize that change first-run wizard customization states.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium315Free2023-05-16Windows LiveKD Kernel Memory Dump Attempt via "-m" Flag
Flags LiveKD executions with the "-m" option that may trigger kernel memory dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2023-05-16