Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Malicious iphlpapi.dll Dropped in OneDrive/Teams AppData Directory
Flags creation of iphlpapi.dll in the Microsoft AppData area used by OneDrive/Teams, consistent with DLL sideloading attempts.
frack113, Huntrule TeamWindowsfile_eventHigh121Free2022-08-12Windows Service Installation of AnyDesk Software (Service Control Manager 7045)
Flags Windows service creation where AnyDesk appears in the service name and ImagePath via SCM Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowssystemMedium353Free2022-08-11Windows Registry: Change to Services\WinSock2\Parameters\AutodialDLL for DLL Persistence
Alerts on registry changes to AutodialDLL under WinSock2 parameters that may enable DLL-based persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh461Free2022-08-10Windows Registry App Paths Default Property Change Using Suspicious Values
Alerts on Windows App Paths registry edits to (Default)/Path with suspicious binaries, scripts, or temp/public locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh93Free2022-08-10Windows Startup Folder File Creation with Suspicious Script/Executable Extensions
Alerts on creation of startup-folder files with script/executable extensions commonly used for logon persistence on Windows.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh314Free2022-08-10Windows Registry Persistence via MyComputer \"Default\" Value Modification
Detects changes to Explorer\MyComputer (Default) registry value that can redirect a launched binary for persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh134Free2022-08-09Windows Persistence Attempt via ErrorHandler.cmd in C:\WINDOWS\Setup\Scripts\
Alerts on writing ErrorHandler.cmd to C:\WINDOWS\Setup\Scripts\, a persistence-relevant location on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium292Free2022-08-09Windows file creation for SharpHound/BloodHound collection output filenames
Flags SharpHound/BloodHound default collection export files (zip and multiple JSON datasets) from Windows file events.
C.J. May, Huntrule TeamWindowsfile_eventHigh111Free2022-08-09Windows SafeBoot Registry Key Deletion via reg.exe Command-Line
Flags reg.exe deleting the \SYSTEM\CurrentControlSet\Control\SafeBoot registry key via command line.
Nasreddine Bencherchali (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh123Free2022-08-08Windows mshta.exe launched with URL-based arguments (http/https/ftp)
Alerts when mshta.exe is executed with HTTP/HTTPS/FTP URLs in the command line, consistent with remote HTA execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh361Free2022-08-08Windows Registry Persistence: DbgManagedDebugger Debugger Value Added
Alerts on registry sets that add a Debugger value under DbgManagedDebugger, indicating potential crash-triggered persistence.
frack113, Huntrule TeamWindowsregistry_setMedium3810Free2022-08-07Windows Process Creation: Detect Use of 8.3 Short Name in Image Path (~1/~2)
Alerts on Windows process launches whose Image path contains 8.3 short-name markers (~1\ or ~2\), excluding several known benign parents.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium373Free2022-08-07Windows Registry RDP Terminal Services Sensitive Settings Tampering
Flags Windows registry changes to sensitive RDP/Terminal Services settings such as shadowing, remote assistance, security, and InitialProgram.
Samir Bousseaden, David ANDRE, Roberto Rodriguez @Cyb3rWard0g, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh124Free2022-08-06Windows Process Creation: Image contains NTFS 8.3 short filename patterns
Flags process creation events where the Image contains Windows 8.3 short-name patterns (e.g., ~1.exe, ~2.ps1) to evade image-based detections.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium376Free2022-08-06Windows Exploit Guard Controlled Folder Access: Added Allowed Application for Blocked Path
Alerts when an app is added to Exploit Guard’s AllowedApplications list to bypass controlled folder restrictions for risky paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh113Free2022-08-05