Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Execution of Htran/NATBypass HackTool Binaries or Tran/Slave CLI Flags
Detects Windows executions of htran.exe or lcx.exe and command lines containing -tran or -slave flags.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-12-27Windows PowerShell Inline Execution via File Reads and Raw Parameters
Alerts on PowerShell command lines that inline-execute content read from files using -raw.
frack113, Huntrule TeamWindowsprocess_creationMedium211Free2022-12-25Windows Process Creation: PowerShell COM CLSID Download Cradles
Alerts on PowerShell command lines using GetTypeFromCLSID with selected CLSIDs that may be used to download files via COM.
frack113, Huntrule TeamWindowsprocess_creationMedium214Free2022-12-25PowerShell ScriptBlock COM CLSID GetTypeFromCLSID Download Cradle Indicators
Alerts on PowerShell script blocks using GetTypeFromCLSID with specific CLSIDs indicative of COM-based download cradles.
frack113, Huntrule TeamWindowsps_scriptMedium301Free2022-12-25Windows PowerShell: In-Memory Assembly Loading via Reflection.Assembly
Flags PowerShell script blocks that reference [Reflection.Assembly]::load for potential in-memory assembly loading.
frack113, Huntrule TeamWindowsps_scriptMedium112Free2022-12-25Windows Process Execution: Suspicious AgentExecutor.exe PowerShell Launch with ExecutionPolicy Bypass
Detects AgentExecutor.exe command lines that trigger PowerShell script execution, including remediations and potentially bypassed ExecutionPolicy.
Nasreddine Bencherchali (Nextron Systems), memory-shards, Huntrule TeamWindowsprocess_creationHigh70Free2022-12-24Windows AgentExecutor.exe PowerShell Execution (ExecutionPolicy Bypass) Process Creation
Alerts on AgentExecutor.exe launches that pass -powershell/-remediationScript to run PowerShell (including bypass execution policy).
Nasreddine Bencherchali (Nextron Systems), memory-shards, Huntrule TeamWindowsprocess_creationMedium70Free2022-12-24Windows Process Copy/Move of Browser Credential Stores
Identifies Windows commands copying or moving browser user data directories consistent with credential theft.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium256Free2022-12-23Windows Process Creation: Suspicious X509Enrollment.CBinaryConverter Execution
Alerts on Windows command lines referencing X509Enrollment.CBinaryConverter with a specific GUID.
frack113, Huntrule TeamWindowsprocess_creationMedium384Free2022-12-23PowerShell FromBase64String Decoding of Base64 Gzip Content in Process Creation on Windows
Windows process command lines using PowerShell FromBase64String with MemoryStream and Gzip-like Base64 markers (H4sI) are flagged.
frack113, Huntrule TeamWindowsprocess_creationMedium422Free2022-12-23Windows PowerShell Execution of AADInternals Cmdlets (process creation)
Flags PowerShell processes running AADInternals “-AADInt” cmdlets, indicating potential Azure AD/Office 365 administration or abuse.
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-12-23Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Alerts on Windows launches of Chromium-based browsers in headless + remote debugging mode targeting a user data directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-12-23Suspicious X509Enrollment usage in Windows PowerShell scripts
Alerts on PowerShell script blocks containing X509Enrollment.CBinaryConverter and a specific enrollment GUID.
frack113, Huntrule TeamWindowsps_scriptMedium123Free2022-12-23PowerShell: FromBase64String Decoding of Gzip (H4sI) into MemoryStream
Identifies PowerShell script blocks that base64-decode and Gzip-unpack embedded content using in-memory streams.
frack113, Huntrule TeamWindowsps_scriptMedium161Free2022-12-23Windows PowerShell Script Block Logging: AADInternals Cmdlets (Add-AADInt to Update-AADInt) Execution
Flags PowerShell script block execution that contains AADInternals cmdlet names (AADInt), indicating potential admin or abuse activity.
Austin Songer (@austinsonger), Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsps_scriptHigh103Free2022-12-23