Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Creation: SharpEvtMute Execution (Event Log Tampering)
Alerts on SharpEvtMute.exe runs with event-log filter and encoded command-line parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2022-09-07Windows SysmonEnte Process Access Attempt (Sysmon.exe/ Sysmon64.exe/ Sysmon64a.exe)
Flags attempts to access Sysmon binaries consistent with SysmonEnte execution based on TargetImage, GrantedAccess, and CallTrace.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh435Free2022-09-07Windows: Detect EvtMuteHook.dll Load by IMPHASH Match (SharpEvtMute)
Detects DLL loads with a specific IMPHASH consistent with EvtMuteHook.dll used for event log tampering.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadHigh92Free2022-09-07Windows suspicious file download URLs using direct IP address with script/binary extensions
Alerts on Windows downloads from HTTP/HTTPS direct IP URLs targeting script/binary/shortcut-like filenames.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh113Free2022-09-07Windows Process Creation: WinAPI Function Names in Command-Line
Alerts on Windows processes whose command lines reference WinAPI functions/modules commonly used for dynamic invocation and memory/process manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-06Windows Process Creation: Renamed Sysinternals Sdelete Execution
Alerts on Windows processes created with OriginalFileName sdelete.exe but executed via renamed sdelete binary paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-09-06Windows PowerShell DNS TXT Download Cradle via nslookup (Process Creation)
Flags PowerShell spawning nslookup configured to query DNS TXT records as a download cradle.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-09-05Windows SharpChisel Command-Line Execution via SharpChisel.exe
Alerts on Windows process executions where the SharpChisel executable or Product metadata indicates SharpChisel.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2022-09-05Windows: Detect QuarksPwDump.exe Credential Dumping via Command-Line Parameters
Flags QuarksPwDump.exe executions on Windows that attempt local/domain hash and related data dumping.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-09-05Windows File Events: Suspicious Executable File Name Creation
Alerts on Windows file creation with suspicious executable filename patterns, including .bat.exe/.sys.exe and deceptive path-based names.
frack113, Huntrule TeamWindowsfile_eventHigh202Free2022-09-05Windows Registry Tampering Targeting Sophos AV Tamper Protection Enabled Flags
Flags Windows registry changes that disable Sophos AV tamper protection by clearing specific enabled DWORD values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh218Free2022-09-02Windows Process Creation: reg.exe Adds or Copies SafeBoot Registry Keys
Flags reg.exe with add/copy used against SafeBoot registry keys in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh463Free2022-09-02Windows Process Execution of Fast Reverse Proxy (FRP) frpc.exe or frps.exe
Alerts on Windows execution of FRP components (frpc.exe/frps.exe) with FRP indicators via command line or known hashes.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh429Free2022-09-02Windows: Detect Ldifde.exe LDAP import (-i -f) usage
Flags Ldifde.exe being run with LDAP import parameters (-i and -f) that may trigger remote content retrieval.
"@gott_cyber, Huntrule Team"Windowsprocess_creationMedium203Free2022-09-02Windows certutil.exe Initiates Network Connections to Common Service Ports
Alerts when certutil.exe initiates outbound network connections to ports 80, 135, 443, or 445 on Windows.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh198Free2022-09-02