Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
Tim Rauch, Janantha Marasinghe, Elastic (original idea), Huntrule TeamWindowsprocess_creationHigh142Free2022-11-08Windows File Creation: Suspicious LNK Double-Extension Targeted by Document/Image Prefixes
Alerts on Windows-created filenames that end in .lnk while containing hidden-looking double extensions (e.g., .doc. .pdf.)
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsfile_eventMedium103Free2022-11-07Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Identifies Windows successful logons consistent with potential access token impersonation using Advapi and Negotiate.
Michaela Adams, Zach Mathis, Huntrule TeamWindowssecurityMedium60Free2022-11-06Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
Ilya Krestinichev, Huntrule TeamWindowsprocess_creationHigh131Free2022-11-03Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh152Free2022-11-03Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh347Free2022-11-01Windows Scheduled Task Creation with GUID-like Task Name
Alerts on schtasks.exe creating scheduled tasks whose /TN value is wrapped GUID-like braces.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-10-31Windows Image Load: Uncommon VSSAPI DLL (vssapi.dll) by Suspicious Executables
Alerts when uncommon processes load vssapi.dll, a Shadow Copy–related DLL, using image load telemetry with path-based exclusions.
frack113, Huntrule TeamWindowsimage_loadHigh100Free2022-10-31Windows Remote Utilities Host Service Installation via Service Control Manager (EventID 7045)
Alerts on Windows Event 7045 when a "Remote Utilities - Host" service is installed from rutserv.exe -service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium151Free2022-10-31Windows Service Installation via NetSupport Manager (Event ID 7045)
Flags Windows service creation for NetSupport Manager Client32 (client32.exe) using Service Control Manager Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium162Free2022-10-31Windows: vsls-agent.exe Executed With --agentExtensionPath Suspicious Library Load
Flags vsls-agent.exe launched with --agentExtensionPath, suggesting a potentially suspicious external extension/library load.
bohops, Huntrule TeamWindowsprocess_creationMedium448Free2022-10-30Windows Named Pipe Creation: PAExec Default Pipe (\PAExec*)
Alerts on named pipe creations starting with "\PAExec" associated with PAExec default behavior on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdMedium4810Free2022-10-26Windows Exchange PowerShell Cmdlet History Log Files Deleted
Flags deletion of Exchange PowerShell cmdlet history log files in the expected logging directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteHigh171Free2022-10-26Windows Service Control Manager: Detect PAExec- service installation
Flags creation of PAExec-named Windows services with image paths under C:\WINDOWS via Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium279Free2022-10-26Windows: Registry change disabling MacroRuntimeScanScope runtime macro scanning
Flags Office registry updates that set MacroRuntimeScanScope to 0x00000000, disabling runtime scanning for enabled macros.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh1610Free2022-10-25