Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows DLL Sideloading Using Antivirus/Vendor DLLs Based on Loaded Image Names
Alerts on suspicious DLL loads matching known antivirus/security component DLL names when not from expected vendor paths.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium323Free2022-08-17Sysmon FileBlockExecutable event: blocked executable execution attempts on Windows
Alerts when Sysmon blocks an attempted executable execution due to FileBlockExecutable policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssysmonHigh4710Free2022-08-16PowerShell Write-EventLog with -RawData Flag
Alerts when PowerShell script blocks call Write-EventLog using the -RawData flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium133Free2022-08-16Windows Process Creation: mshtml.dll RunHTMLApplication Execution via Protocol Handlers
Alerts on Windows command lines invoking mshtml.dll RunHTMLApplication (via #135) with path traversal markers.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Josh Nickels, frack113, Zaw Min Htun (ZETA), Huntrule TeamWindowsprocess_creationHigh251Free2022-08-14Windows Firewall rule deleted via netsh.exe command line
Flags netsh.exe executions that contain Windows Firewall rule deletion commands.
frack113, Huntrule TeamWindowsprocess_creationMedium113Free2022-08-14Windows DLL Sideloading: System DLL Names Loaded from Non-Standard Paths (ImageLoad)
Alerts when Windows image loads DLL names typically found in system locations, excluding common benign paths to reduce false positives.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh1910Free2022-08-14Windows rundll32 Loading Renamed comsvcs.dll via DLL Image Load
Flags rundll32.exe loading a renamed comsvcs.dll module consistent with process memory dumping behavior on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2022-08-14Windows Shell-Core: Installed Application Shortcut Indicators for Known Tools
Flags suspicious installation-style activity in Windows shell-core based on EventID 28115 app resolver cache entries for specific tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsshell-coreMedium427Free2022-08-14Windows: Detect ESENT New Database Created with ntds.dit Written to Suspicious Path
Identifies ESENT EventID 325 where a new database containing ntds.dit is created in suspicious locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium90Free2022-08-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium120Free2022-08-14Windows: Unusual Process Tree for wab.exe and wabmig.exe
Alert on abnormal parent/child process relationships involving wab.exe and wabmig.exe in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh202Free2022-08-12Windows Process Creation: wab.exe or wabmig.exe Run from Non-Default Paths
Alerts when wab.exe or wabmig.exe run from unexpected directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh198Free2022-08-12Windows: User Added to Local Administrators Group via Net or Add-LocalGroupMember
Flags Windows command lines that add a user to the local administrators group via net.exe or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium465Free2022-08-12Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-08-12Windows file write events where executables save files with suspicious script/binary extensions
Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2022-08-12