Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Suspicious Execution of Regasm/Regsvcs With Uncommon Command-Line Extension
Flags Regasm.exe/Regsvcs.exe runs that include unusual extensions in the command line, which may indicate stealthy misuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium241Free2023-02-13Windows: Filter Driver Unload via fltMC.exe
Flags fltMC.exe executions that include "unload" to indicate potential filter driver unloading for defense impairment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2023-02-13Windows: Suspicious Executable Created in Temp by OneNote (onenote.exe/onenotem.exe/onenoteim.exe)
Alerts when OneNote creates files in Temp\OneNote with script/executable extensions on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh141Free2023-02-09Windows Registry: Outlook EnableUnsafeClientMailRules Set to 1
Alerts when Outlook’s EnableUnsafeClientMailRules registry value is enabled (DWORD 0x1), reducing mailbox macro/script protections.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh112Free2023-02-08Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Alerts on Windows executions referencing gatherNetworkInfo.vbs in process command lines, indicative of potential discovery activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh295Free2023-02-08Windows: Outlook loads outlvba.dll (VBA for Outlook add-in) via image loading
Alerts on outlvba.dll being loaded by outlook.exe, indicating VBA add-in execution within Outlook.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium152Free2023-02-08Windows: .pub File Creation in Temp or Public Directories
Alerts on creation of .pub files in Temp/Public-like directories on Windows where staging is likely.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium419Free2023-02-08Windows: Suspicious Outlook VbaProject.OTM Macro File Created
High-confidence file creation alert for Microsoft\Outlook\VbaProject.OTM while excluding outlook.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh206Free2023-02-08Windows File Events: VBS gatherNetworkInfo results file creation
Flags Windows file writes under System32\config consistent with gatherNetworkInfo.vbs network reconnaissance output.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium239Free2023-02-08Windows Process Creation: Renamed AutoHotkey Executable via PE Metadata
Detects renamed AutoHotkey executables by correlating process creation events with PE metadata indicators.
Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium132Free2023-02-07Windows nltest.exe Execution for Network Information Discovery
Flags execution of nltest.exe (including nltestrk.exe via OriginalFileName) used for network and domain information discovery.
Arun Chauhan, Huntrule TeamWindowsprocess_creationLow140Free2023-02-03Windows cmdkey.exe Adds Generic Credentials via -g Flag
Flags -g/-u/-p with cmdkey.exe indicate generic credential insertion, which can enable follow-on access.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium464Free2023-02-03Windows OneNote.exe launches cmd/cscript/mshta/PowerShell/wscript with OneNote-exported scripts
Alerts when OneNote.exe spawns common script interpreters to execute OneNote-exported or offline-cache script content.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh90Free2023-02-02Windows: PowerShell Add-AppxPackage Attempt With -AllowUnsigned for AppX Installation
Detects PowerShell Add-AppxPackage usage with -AllowUnsigned to install unsigned AppX packages.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium447Free2023-01-31Windows PowerShell: Add-AppxPackage with -AllowUnsigned for Unsigned AppX Installation
Flags PowerShell usage of Add-AppxPackage/Add-AppPackage with -AllowUnsigned to install unsigned AppX packages.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium123Free2023-01-31