Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh101Free2023-01-11Windows AppX Deployment Failure (0x80073cff) Due to Signing Requirements
Alerts on Windows AppX deployments/installations failing with 0x80073cff, consistent with unmet signing requirements.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium162Free2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh426Free2023-01-11Windows AppX deployment blocked by AppLocker (AppXDeployment-Server EventID 412)
Flags AppX package deployment attempts that AppLocker blocked, based on AppXDeployment-Server EventID 412.
frack113, Huntrule TeamWindowsappxdeployment-serverMedium273Free2023-01-11Windows Process Creation: PowerShell Import-Module from Temp/AppData/Public Paths
Alerts on PowerShell Import-Module calls that load modules from Temp, AppData, or Public directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium406Free2023-01-10PowerShell script alias obfuscation via -Value (-join(...))
Flags PowerShell script blocks that set aliases using -Value with a (-join(...)) character-joining obfuscation pattern.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptLow417Free2023-01-09Windows PowerShell Script Block Alerts for Set-Alias and New-Alias Usage
Alerts on PowerShell scripts that create aliases via Set-Alias/New-Alias, a common obfuscation technique, using ScriptBlockText logging.
frack113, Huntrule TeamWindowsps_scriptLow485Free2023-01-08Windows Suspicious Double-Extension Execution via Parent Command Line
Alerts on Windows processes launched by parents whose image/command line includes disguised double-extension tokens.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh169Free2023-01-06Windows PowerShell Process Creation: Suspicious Base64/Encoded and IEX WebClient Patterns
Detects suspicious PowerShell process command lines using hidden/no-profile, execution-policy bypass, and encoded/Base64 or IEX WebClient download patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-01-05Windows PowerShell: ScriptBlock using security descriptor (Win32_Trustee/Win32_Ace) and LSA data strings
Alerts on PowerShell ScriptBlock text that manipulates security descriptors and LSA-related identifiers, indicating possible persistence behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh352Free2023-01-05Windows Registry AMSI COM Server Hijacking via InProcServer32 CLSID Modification
Alerts on registry changes that alter an AMSI COM CLSID InProcServer32 entry to break AMSI loading.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh438Free2023-01-04Windows PowerShell Keylogger Function Reference in Script Block Logging
Alerts on PowerShell script blocks containing keyboard IsKeyDown references associated with potential keystroke capture.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium111Free2023-01-04Windows Process Creation: Suspicious Git Clone Command With Vulnerability Keywords
Flags Windows git clone commands that include exploit/vulnerability-style keywords in the process command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium469Free2023-01-03Windows Registry EventLog Service File Location Tampering
Flags registry modifications that change the EventLog service’s configured log file location on Windows.
D3F7A5105, Huntrule TeamWindowsregistry_setHigh161Free2023-01-02Windows Ruby Inline Code Execution via Ruby.exe -e Flag
Flags Windows executions of ruby.exe that include the inline code flag (-e) for direct command-line Ruby code.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium183Free2023-01-02