Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: WinSxS .exe Creation Triggered by Non-System Process
Flags .exe creation in C:\Windows\WinSxS\ when the creating process is not from standard system directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium113Free2023-05-11PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh235Free2023-05-09Windows: New PowerShell Module Files Created by Non-PowerShell Processes
Detects new PowerShell module files written into Modules directories by processes other than expected PowerShell hosts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium141Free2023-05-09Windows PowerShell Module File Creation via PowerShell Processes
Alert when PowerShell creates module-related files under WindowsPowerShell or PowerShell 7 module directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow152Free2023-05-09Windows PowerShell dropping a .ps1 script from powershell.exe or pwsh.exe
Alerts when PowerShell creates a dropped .ps1 script file on Windows, excluding common benign temp and test outputs.
frack113, Huntrule TeamWindowsfile_eventLow374Free2023-05-09System Informer Execution on Windows Process Creation
Alerts on Windows executions of SystemInformer.exe using matching filenames, metadata, and known hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-05-08Windows File Event: Flag Cyrillic Homoglyph Characters in Target Filename
Alerts on Windows file events with TargetFilename containing ASCII lookalike Unicode characters.
Micah Babinski, @micahbabinski, Huntrule TeamWindowsfile_eventMedium283Free2023-05-08Windows PUA System Informer Driver Load via SystemInformer.sys
Alerts on loading SystemInformer.sys as a Windows driver when matched against known System Informer SHA256 hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadMedium81Free2023-05-08Windows Process Command Line Matches Perfect Homoglyph Unicode Characters
Alerts when a Windows process command line includes Unicode homoglyphs that look like ASCII letters.
Micah Babinski, @micahbabinski, Huntrule TeamWindowsprocess_creationMedium162Free2023-05-07Windows ImageLoad of SolidPDFCreator.dll from Unexpected Paths
Alerts when SolidPDFCreator.dll is loaded from a non-standard process or path, consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium71Free2023-05-07Windows Wget.exe Downloads From File-Sharing Domains Matching Suspicious Output Flags
Flags wget.exe executions on Windows that download via HTTP from known file-sharing domains and write specific file extensions to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh425Free2023-05-05Windows curl.exe Downloads from File-Sharing Domains with Suspicious Output Extensions
Alerts on curl.exe downloading files over HTTP from file-sharing/content hosting domains, based on process command-line and executable context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-05-05PowerShell Script Reading Files and Resolving DNS Host Entries
Identifies PowerShell scripts that read files, resolve DNS host entries, and output results to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium1810Free2023-05-05Windows DLL Sideloading: libcurl.dll Loaded by gup.exe from Uncommon Location
Alerts when gup.exe loads libcurl.dll from a path that doesn’t match the excluded Notepad++ GUP.exe location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium415Free2023-05-05Windows: File creation of a Procmon-named .sys driver by non-procmon processes
Alerts when a procmon-named .sys driver is created by a process other than procmon.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium132Free2023-05-05