Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Network Connections by wscript/cscript Script Interpreters to Non-Local IPs
Flags wscript.exe/cscript.exe making outbound connections to non-local destination IPs.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh141Free2022-08-28Windows Wscript/Cscript Initiating Local Network Connection for Script Retrieval
Flags wscript.exe or cscript.exe making connections to local/private destination IP ranges on Windows.
frack113, Huntrule TeamWindowsnetwork_connectionMedium93Free2022-08-28Windows Scheduled Task Index Registry Tampering Hiding Tasks from Query Tools
Alerts on registry set events that tamper scheduled task TaskCache Tree "Index" DWORD to 0.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh123Free2022-08-26Windows Registry: Scheduled Task Index Value Removal to Hide Task (TaskCache)
Alerts on deletion of the Scheduled Tasks TaskCache Tree 'Index' value used by tools to enumerate tasks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_deleteMedium151Free2022-08-26Suspicious SysAidServer Child Processes via Java on Windows
Flags SysAidServer process spawning java.exe/javaw.exe on Windows to surface likely suspicious execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2022-08-26Windows Process Execution: Suspicious PowerShell Encoded Command with Exec Bypass
Flags Windows process creations with a bypass-and-encoded PowerShell Start-Job command-line pattern linked to Mercury-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh324Free2022-08-26Windows Process Execution of Regasm/Regsvcs from Uncommon Directories
Alerts on Regasm/Regsvcs executions from commonly abused non-standard directories using process creation image and command line fields.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2022-08-25Windows process command line matching Sliver C2 implant NoExit PowerShell UTF8 pattern
Alerts on Windows process command lines matching a Sliver-style PowerShell -NoExit encoding pattern.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical152Free2022-08-25Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh264Free2022-08-25Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2022-08-24Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Flags Sysinternals-related registry EULA acceptance writes tied to PsExec/ProcDump/Process Explorer and other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium70Free2022-08-24Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Flags registry writes to EulaAccepted for Sysinternals-named targets when executed by non-matching image filenames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh70Free2022-08-24Windows File Changes to Microsoft.VSCode_profile.ps1 via PowerShell Profile
Detects creation or modification of Microsoft.VSCode_profile.ps1 based on Windows file events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium91Free2022-08-24Windows msdt.exe Creating Files in Common Startup and Public Directories
Alerts when msdt.exe writes files to high-suspicion directories that may indicate persistence after exploitation.
Vadim Varganov, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-08-24Windows Named Pipe Stream Created with Known Hack Tool IMPHASHs
Alerts on Windows named file stream creation events whose IMPHASH matches common hack-tool binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh122Free2022-08-24