Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Defender mpclient.dll Side-loading: MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when MpCmdRun.exe or NisSrv.exe runs from non-default directories, a common indicator of possible mpclient.dll sideloading.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh404Free2022-08-01Windows dnscmd.exe DNS Zone and Record Enumeration Command Execution
Flags dnscmd.exe executions that enumerate DNS zones/records via process creation command-line parameters.
"@gott_cyber, Huntrule Team"Windowsprocess_creationMedium337Free2022-07-31Windows ISO File Creation in User Temp and Outlook Cache Folders
Alerts on creation of .iso files in Windows AppData temp or Outlook cache paths.
"@sam0x90, Huntrule Team"Windowsfile_eventHigh91Free2022-07-30Windows DLL Search Order Hijack via Space in System Directory Paths
Alerts on .dll events targeting Windows system paths with an extra space, indicative of DLL search order hijacking.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh346Free2022-07-30Windows Sysmon Driver Altitude Registry Changes
Identifies registry writes that change the Sysmon instance altitude value, which can disrupt Sysmon loading at boot.
B.Talebi, Huntrule TeamWindowsregistry_setHigh123Free2022-07-28Windows schtasks Scheduled Task Create/Modify Running as SYSTEM
Alerts on Windows schtasks task create/modify commands that set the run account to NT AUTHORITY\SYSTEM.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh195Free2022-07-28Windows: Suspicious Scheduled Task Modification via schtasks /Change /TN
Flags schtasks.exe executions that modify existing scheduled tasks (/Change /TN) using suspicious locations and command-line payload tooling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh438Free2022-07-28Windows File Creation: Suspicious DLL/EXE/SYS in Spool Drivers Color Folder
Alerts on creation of .dll, .exe, or .sys files under C:\Windows\System32\spool\drivers\color.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium111Free2022-07-28Windows Registry: Appx DebugPath Key for Potential Persistence
Detects registry set activity involving AppX DebugPath entries that may indicate persistence via packaged app debug configuration.
frack113, Huntrule TeamWindowsregistry_setMedium408Free2022-07-27Windows Browser Launched with Remote Debugging Flags
Alerts on Windows launches of Chromium-based browsers or Firefox with remote debugging command-line flags.
pH-T (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium144Free2022-07-27Windows: WinRing0 Driver Load via Image Hash and File Name Match
Alerts on Windows driver loads matching WinRing0 modules by IMPhash or expected WinRing0 filenames.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh162Free2022-07-26Windows: Detect SelectMyParent PPID Spoofing Tool Execution
Flags SelectMyParent.exe process creation with PPID spoofing command-line and metadata indicators on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-07-23Suspicious PDQDeployRunner Execution on Windows with Encoded/Download Indicators
Alerts on child process activity from PDQDeployRunner parents showing encoded, hidden, or download-related command line indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-07-22Windows Service Installation: PDQDeployRunner Remote Service Creation (Service Control Manager)
Flags new Windows services installed with PDQDeployRunner-* naming via Service Control Manager event 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium153Free2022-07-22Windows: Detect New PDQDeploy Service Installation via Service Control Manager
Flags new Windows services installed via SCM Event 7045 that reference PDQDeployService.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium141Free2022-07-22