Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)
Alerts on Windows process launches with command lines containing Unicode U+202E to support right-to-left text obfuscation.
Micah Babinski, @micahbabinski, Swachchhanda Shrawan Poudel (Nextron Systems), Luc Génaux, Huntrule TeamWindowsprocess_creationHigh82Free2023-02-15Windows: certutil.exe ExportPFX certificate export via -exportPFX flag
Flags certutil.exe executions on Windows that include the -exportPFX argument to export certificate material.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium394Free2023-02-15Windows: certutil.EXE Downloading Files from File-Sharing Domains via Suspicious Flags
Alert when certutil.exe is run with URL/download flags targeting common file-sharing domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh150Free2023-02-15Windows certutil.exe Download from Direct IP Using URL/IP-Related Flags
Alerts when certutil.exe is launched with direct-IP download indicators and download-capable certutil flags.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh183Free2023-02-15Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
Alerts on certutil.exe runs with URL/HTTP-related flags indicative of remote file download.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-02-15Windows certutil.exe Base64/Hex Decode via -decode or -decodehex Flags
Flags certutil.exe use for decoding base64 or hex data via -decode or -decodehex on Windows.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh132Free2023-02-15Windows: CertOC.exe Loading a DLL from User-Writable Paths via -LoadDLL
Alerts on CertOC.exe using -LoadDLL with DLLs from temp/user-writable directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-02-15Windows PowerShell Console History File Deleted (PSReadLine)
Flags deletion of the PowerShell PSReadLine ConsoleHost_history.txt file, which can remove command history evidence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium102Free2023-02-15Windows Event Log EVTX File Deletion in winevt\Logs
Flags deletion of Windows Event Log .evtx files under System32\winevt\Logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteMedium313Free2023-02-15Windows WMIC Remote Query Execution via /node
Identifies remote WMIC queries on Windows by matching WMIC execution with /node: in the command line.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-02-14Windows WMIC.exe Service Reconnaissance via Remote Service Queries
Flags WMIC.exe commands containing service-related reconnaissance strings while excluding stop/start service manipulation.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium355Free2023-02-14Windows WMIC.exe Product Class Reconnaissance via Security Product Queries
Detects wmic.exe being used to enumerate firewall, antivirus, and antispyware product classes.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium1910Free2023-02-14Windows WMIC Product Reconnaissance via Firewall/AV Enumeration
Alerts on wmic.exe executions with command lines consistent with Windows product enumeration for reconnaissance.
Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium154Free2023-02-14Windows wmic.exe Hardware Model Reconnaissance Using csproduct
Flags wmic.exe executions that include "csproduct" to query hardware model/vendor details.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium359Free2023-02-14Windows execution of LocalPotato POC (LocalPotato.exe with specific PE/CLI traits)
Detects LocalPotato.exe process execution on Windows using image path, typical CLI parameters, and known imphash values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2023-02-14