Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Flags Windows service installation or updates for remote access tool services using Service Control Manager events.
Connor Martin, Nasreddine Bencherchali, Huntrule TeamWindowssystemMedium488Free2022-12-23Windows Security Event 4697 Service Install of Remote Access Tools
Alerts on Windows service creation (EID 4697) where the service name matches known remote access tool indicators.
Connor Martin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityMedium133Free2022-12-23Windows: Explorer opened from cmd.exe/powershell using shell:MyComputerFolder shortcut
Flags explorer.exe opened for My Computer via shell:mycomputerfolder when started by cmd or PowerShell.
"@Kostastsale, Huntrule Team"Windowsprocess_creationHigh233Free2022-12-22Windows Process Creation: Impersonate.exe HackTool Execution
Flags execution of impersonate.exe (Impersonate tool) on Windows using command-line subcommands or known hashes.
Sai Prashanth Pulisetti @pulisettis, Huntrule TeamWindowsprocess_creationMedium81Free2022-12-21Windows Registry Set Detection of Suspicious Environment Variable Commands
Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh297Free2022-12-20Windows Office Binary Execution with Renamed Image Path
Alerts when Office apps are executed under renamed or unexpected image paths, helping catch stealthy masquerading on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-12-20Windows SQLite CLI Querying Chromium Browser Profile Databases
Alerts when SQLite CLI is used to query Chromium-based browser profile databases containing logins, cookies, or history.
TropChaud, Huntrule TeamWindowsprocess_creationHigh228Free2022-12-19Windows DLL Sideloading via comctl32.dll in .local directories
Alerts on comctl32.dll loaded from System32 .local folders, consistent with Windows DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Subhash Popuri (@pbssubhash), Huntrule TeamWindowsimage_loadHigh4310Free2022-12-16Windows File Events: Suspicious .exe.local Path With comctl32.dll in System32
Detects System32 *.exe.local entries that reference comctl32.dll, consistent with DLL sideloading behavior.
Nasreddine Bencherchali (Nextron Systems), Subhash P (@pbssubhash), Huntrule TeamWindowsfile_eventHigh161Free2022-12-16Windows DLL Sideloading Indicator: JsSchHlp Loads JSESPR.dll from Untrusted Path
Alerts on unexpected loads of \JSESPR.dll, indicating possible DLL sideloading outside the Justsystem JsSchHlp directory.
frack113, Huntrule TeamWindowsimage_loadMedium153Free2022-12-14Windows DLL Sideloading: ClassicExplorer32.dll Loaded from Unexpected Path
Alerts when ClassicExplorer32.dll is loaded from unexpected locations, suggesting possible DLL sideloading behavior.
frack113, Huntrule TeamWindowsimage_loadMedium102Free2022-12-13Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.
frack113, Huntrule TeamWindowsregistry_setHigh163Free2022-12-11Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Identifies uncommon setres.exe children matching '\choice' while excluding System32/SysWOW64 choice.exe.
"@gott_cyber, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Windowsprocess_creationHigh172Free2022-12-11Windows: Detect rcedit editing PE version/resource metadata via --set-*
Alerts on rcedit command-line usage that sets PE metadata fields to alter executable file properties.
Micah Babinski, Huntrule TeamWindowsprocess_creationMedium143Free2022-12-11Windows Privilege Escalation via mklink Symlink Between cmd.exe and osk.exe
Alerts on mklink creating a symlink between osk.exe and cmd.exe, enabling potential login-screen privilege escalation.
frack113, Huntrule TeamWindowsprocess_creationHigh4410Free2022-12-11