Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows LiveKD Driver File Creation by Uncommon Process Image
Alerts when LiveKdD.SYS is created by a process other than livekd.exe/livek64.exe on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh111Free2023-05-16Windows LiveKD Driver Creation via LiveKdD.SYS and LiveKD Executable Launch
Detects creation of LiveKdD.SYS in the Windows drivers directory by LiveKD executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium103Free2023-05-16Windows: LiveKD kernel memory dump file creation (livekd.dmp)
Flags creation of C:\Windows\livekd.dmp, a default LiveKD kernel memory dump file name.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh317Free2023-05-16Windows Wscript/Cscript Executes Files with Uncommon Non-Script Extensions
Flags wscript.exe/cscript.exe launching files named with uncommon non-script extensions via command-line content.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2023-05-15Suspicious rundll32/regsvr32/msiexec Child Process from Windows Script Hosts (cscript/wscript)
Alerts on wscript/cscript spawning suspicious child processes or scripts that invoke rundll32/regsvr32/msiexec.
Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'), Huntrule TeamWindowsprocess_creationMedium124Free2023-05-15Windows Process Creation: LiveKD Execution Suggesting Potential Memory Dumping
Detects launching LiveKD (livekd.exe/livekd64.exe) on Windows via image path or PE OriginalFileName metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-05-15Windows Process Creation of Kernel Debugger kd.exe
Flags Windows process creations that run kd.exe using image path and OriginalFileName metadata.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium227Free2023-05-15Suspicious Child Process of GoogleUpdate.exe on Windows
Alerts when GoogleUpdate.exe spawns an unexpected child process on Windows, using parent/child image telemetry and allowlisting common Google updaters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2023-05-15Windows Process Creation: certutil.exe Encodes Files to Base64 in Suspicious Paths
Alert on certutil.exe running with -encode when the command line references files under suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh120Free2023-05-15Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions
Alert on certutil.exe -encode activity that targets files with suspicious extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2023-05-15Windows DLL Sideloading: goopdate.dll Loaded from Nonstandard Paths
Alerts when goopdate.dll is loaded from non-standard locations, suggesting possible DLL sideloading behavior on Windows.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium443Free2023-05-15Windows RoboForm DLL Sideloading via ImageLoaded roboform.dll/roboform-x64.dll
Alerts on loaded roboform*.dll modules on Windows when module loading is not matched to expected RoboForm binaries.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium447Free2023-05-14Windows Certificate Export from Local Certificate Store (Event ID 1007)
Flags Windows events where a certificate is exported from the local certificate store via Certificate Services client telemetry.
Zach Mathis, Huntrule TeamWindowscertificateservicesclient-lifecycle-systemMedium113Free2023-05-13Windows CAPI2 Event 70: Certificate Private Key Acquired
Detects when Windows CAPI2 logs that a process acquired a certificate private key (EventID 70).
Zach Mathis, Huntrule TeamWindowscapi2Medium151Free2023-05-13Windows Excel Loads .XLL Add-in from Uncommon File Paths
Flags Excel loading .xll add-ins from uncommon directories based on image load paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium93Free2023-05-12