Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Flags Sysinternals ADExplorer running with "snapshot" to create a local Active Directory database copy.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-03-14Windows AD Structure Export Using ldifde.exe with -f
Flags ldifde.exe executions using -f that indicate Active Directory structure export from a Windows host.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-03-14Windows Process Creation: dotnet-dump.exe collect Flag
Flags dotnet-dump.exe executions using the collect parameter, which may indicate memory dumping of sensitive processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-03-14Windows: Detect csvde.exe Active Directory export to CSV
Flags csvde.exe executions on Windows that include -f, consistent with exporting Active Directory data for discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium237Free2023-03-14Windows Registry Event for Potential Qakbot/IceID Persistence Key
Alerts on Windows registry events referencing a specific \\Software\\firm\\soft\\Name key suffix linked to Qakbot/IceID-like activity.
Hieu Tran, Huntrule TeamWindowsregistry_eventHigh132Free2023-03-13Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
Hieu Tran, Huntrule TeamWindowsprocess_creationHigh91Free2023-03-13Windows PowerShell Downloading DLLs via Invoke-WebRequest or Invoke-RestMethod
Alerts on PowerShell using web request cmdlets to download an HTTP DLL to disk.
Florian Roth (Nextron Systems), Hieu Tran, Huntrule TeamWindowsprocess_creationMedium70Free2023-03-13PowerShell GzipStream Decompression Attempts on Windows
Detects Windows PowerShell commands using GZipStream and ::Decompress to decompress encoded Gzip data.
Hieu Tran, Huntrule TeamWindowsprocess_creationMedium123Free2023-03-13Windows Wazuh Platform DLL Side-Loading via ImageLoad of libwazuhshared.dll
Alerts on suspicious loading of Wazuh platform DLLs in Windows image load telemetry, excluding common Program Files and Mingw64 patterns.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium151Free2023-03-13Windows Rcdll.dll DLL Sideloading via Image Load Path
Flags rcdll.dll loads from unexpected locations, excluding Visual Studio and Windows Kits directories.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh133Free2023-03-13Windows Sysmon Configuration Update via Sysmon64 Command-Line
Flags execution of Sysmon binaries with '-c', indicating a Sysmon configuration update attempt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-03-09Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh197Free2023-03-08Windows cmd.exe Reads Input from STDIN Using '<' Redirection
Flags cmd.exe invocations with '<' in the command line, indicating stdin/input redirection.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium422Free2023-03-07Windows: Stop a Service with sc.exe via Process Creation (sc.exe stop)
Identifies sc.exe executions that include 'stop' to stop Windows services based on process creation and command line.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow192Free2023-03-05Windows PowerShell Stop-Service Used to Stop a Service
Flags PowerShell executions that include the Stop-Service cmdlet to stop a Windows service.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow131Free2023-03-05