Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows image_load Suspicious libvlc.dll DLL sideloading via non-VLC paths
Alerts when libvlc.dll is loaded from a non-default path, suggesting potential VLC DLL sideloading on Windows.
X__Junior, Huntrule TeamWindowsimage_loadMedium133Free2023-04-17Windows: Unexpected Termination of Message Queuing (MSMQ) Service via SCM Event 7034
Flags Service Control Manager Event ID 7034 for unexpected termination of the Message Queuing (MSMQ) service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh241Free2023-04-14Windows Service Control Manager: Termination of Security-Critical Services With Error
Alerts on error-terminated Windows security and infrastructure services from Service Control Manager event 7023.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh182Free2023-04-14Windows Service Terminated With Error (Service Control Manager Event 7023)
Alerts on Windows services terminated with an error as reported by the Service Control Manager (EventID 7023).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemLow130Free2023-04-14Windows: Renamed Visual Studio NodejsTools PressAnyKey.exe Execution
Flags Windows executions of renamed Microsoft.NodejsTools.PressAnyKey.exe to help spot LOLBIN-style abuse.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3010Free2023-04-11Windows: Logged-On User Password Change via ksetup.exe
Flags ksetup.exe executions with /ChangePassword that may indicate a logged-on user password change on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2023-04-06Windows Password Change via ksetup.exe /setcomputerpassword
Alerts on Windows ksetup.exe executions that set a computer password via /setcomputerpassword.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-04-06Windows Defender Real-Time Protection Error or Restart (windefend Event 3002/3007)
Alerts on windefend events showing Defender Real-Time Protection feature errors (3002) or restarts (3007).
Nasreddine Bencherchali (Nextron Systems), Christopher Peacock '@securepeacock' (Update), Huntrule TeamWindowswindefendMedium3410Free2023-03-28Windows Process Creation: Sysinternals PsSuspend Targeting msmpeng.exe
Alerts on execution of Sysinternals PsSuspend with command line referencing msmpeng.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh488Free2023-03-23Windows Sysinternals PsSuspend Process Execution
Alerts on execution of Sysinternals PsSuspend on Windows via process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium80Free2023-03-23Windows DLL sideloading: iviewers.dll loaded from non-Windows Kits paths
Alerts on unexpected loads of iviewers.dll outside Windows Kits paths, consistent with DLL sideloading attempts.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2023-03-21Windows PowerShell File Dropper Activity: Creating Executables or Script Files
Alerts when PowerShell writes .exe/.dll or script-like files, consistent with binary/script staging or dropping.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium151Free2023-03-17Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
Alerts on svchost.exe launching rundll32.exe to run davclnt.dll DavSetCookie for WebDav over a non-local IP.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2023-03-16Windows Registry: Hypervisor Enforced Code Integrity Enabled DWORD Set to 0
Alerts when HVCI-related registry values are set to 0, indicating Hypervisor Enforced Code Integrity has been disabled.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsregistry_setHigh141Free2023-03-14Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-03-14