Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows PsExec Remote Execution Creates PSEXEC-*.key File Artefact
Alerts on creation of PsExec key files in C:\Windows\PSEXEC-*.key, indicating remote execution activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3010Free2023-01-21Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Alerts on PowerShell module payloads containing commandlet/function names from known malicious exploitation and post-exploitation frameworks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_moduleHigh132Free2023-01-20Windows driverquery.exe Process Execution Detection
Alerts on Windows executions of driverquery.exe (drvqry.exe) used to enumerate installed drivers, with parent-process exclusions to reduce duplicates.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2023-01-19Windows: driverquery.exe Usage for Installed Driver Recon
Alerts when driverquery.exe (drvqry.exe) is launched by script-based parent processes to enumerate installed drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh203Free2023-01-19Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
Flags successful Windows SMB (LogonType 3) logons from non-private, non-local source IP addresses.
Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity), Huntrule TeamWindowssecurityHigh60Free2023-01-19Windows RDP Successful Logon (4624 LogonType 10) from Public IP
Alerts on successful RDP (LogonType 10) from a non-private, non-local source IP in Windows Security Event 4624.
Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity), Huntrule TeamWindowssecurityMedium90Free2023-01-19Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-01-18Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Alerts on Windows Defender Firewall configurations where all rules are deleted (Event 2033/2059), signaling potential defense impairment.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asHigh163Free2023-01-17PowerShell Data Exfiltration Using Audio File (WAV BinaryWriter) on Windows
Alerts on PowerShell script blocks that appear to write data into an audio (WAV) file for potential exfiltration.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium142Free2023-01-16Windows DNS Client: DNS queries containing "ufile.io"
Alerts on Windows DNS Client queries where the queried name includes "ufile.io".
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientLow173Free2023-01-16Windows DNS Client: MEGA userstorage subdomain DNS query (EventID 3008)
Detects Windows DNS client queries for MEGA userstorage subdomains by matching the query name string.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientMedium122Free2023-01-16Windows DNS Client: Cobalt Strike DNS Beaconing Patterns via Suspicious Query Names
Alerts when Windows DNS client logs show Event ID 3008 DNS queries matching Cobalt Strike beacon patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientCritical4410Free2023-01-16Windows DNS Client: DNS query for anonfiles.com domain
Alerts when Windows DNS client logs show a DNS query containing .anonfiles.com.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientHigh171Free2023-01-16Windows AppX Packaging: Execute AppX with Suspicious Digital Signature Certificate
Alerts when AppX package execution/signature subject matches a known suspicious certificate in Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxpackaging-omMedium122Free2023-01-16Windows AppX Execution of Sysinternals Tools (procdump/psloglist/psexec/livekd/ADExplorer)
Flags execution of common Sysinternals binaries when launched through the Windows AppX runtime.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappmodel-runtimeLow336Free2023-01-16