Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Wscript/Cscript Initiating Local Network Connection for Script Retrieval
Flags wscript.exe or cscript.exe making connections to local/private destination IP ranges on Windows.
frack113, Huntrule TeamWindowsnetwork_connectionMedium123Free2022-08-28Windows Scheduled Task Index Registry Tampering Hiding Tasks from Query Tools
Alerts on registry set events that tamper scheduled task TaskCache Tree "Index" DWORD to 0.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh123Free2022-08-26Windows Registry: Scheduled Task Index Value Removal to Hide Task (TaskCache)
Alerts on deletion of the Scheduled Tasks TaskCache Tree 'Index' value used by tools to enumerate tasks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_deleteMedium171Free2022-08-26Suspicious SysAidServer Child Processes via Java on Windows
Flags SysAidServer process spawning java.exe/javaw.exe on Windows to surface likely suspicious execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2022-08-26Windows Process Execution of Regasm/Regsvcs from Uncommon Directories
Alerts on Regasm/Regsvcs executions from commonly abused non-standard directories using process creation image and command line fields.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium91Free2022-08-25Windows process command line matching Sliver C2 implant NoExit PowerShell UTF8 pattern
Alerts on Windows process command lines matching a Sliver-style PowerShell -NoExit encoding pattern.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical152Free2022-08-25Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh264Free2022-08-25Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2022-08-24Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Flags Sysinternals-related registry EULA acceptance writes tied to PsExec/ProcDump/Process Explorer and other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium70Free2022-08-24Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Flags registry writes to EulaAccepted for Sysinternals-named targets when executed by non-matching image filenames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh70Free2022-08-24Windows File Changes to Microsoft.VSCode_profile.ps1 via PowerShell Profile
Detects creation or modification of Microsoft.VSCode_profile.ps1 based on Windows file events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium91Free2022-08-24Windows msdt.exe Creating Files in Common Startup and Public Directories
Alerts when msdt.exe writes files to high-suspicion directories that may indicate persistence after exploitation.
Vadim Varganov, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh267Free2022-08-24Windows Named Pipe Stream Created with Known Hack Tool IMPHASHs
Alerts on Windows named file stream creation events whose IMPHASH matches common hack-tool binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh122Free2022-08-24Windows Suspicious File Download Streams From File/Paste Hosting Domains With Script Extensions
Alert on Windows file stream hash creation involving downloads from paste/file-sharing domains targeting .bat/.cmd/.ps1 content indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashMedium171Free2022-08-24Windows CreateStreamHash: Suspicious Downloads From File Sharing and Paste Websites
Identifies Windows stream-hash events tied to downloads from file-sharing/paste domains with Zone-tagged payload extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh70Free2022-08-24