Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Suspicious File Download Streams From File/Paste Hosting Domains With Script Extensions
Alert on Windows file stream hash creation involving downloads from paste/file-sharing domains targeting .bat/.cmd/.ps1 content indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashMedium171Free2022-08-24Windows CreateStreamHash: Suspicious Downloads From File Sharing and Paste Websites
Identifies Windows stream-hash events tied to downloads from file-sharing/paste domains with Zone-tagged payload extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh60Free2022-08-24Windows Registry: New NetworkProvider service keys indicative of credential dumping
Alerts on registry additions/changes to NetworkProvider service entries that may be used to dump clear-text credentials.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium247Free2022-08-23Windows Process Creation Using the Sysnative Directory Path
Alerts on process executions referencing \Windows\Sysnative, excluding common ngen.exe and a known XAMPP bat launcher.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2022-08-23Windows Process Creation: Suspicious CLI NetworkProvider Addition for Credential Dumping
Alerts on Windows CLI executions that reference services\... and NetworkProvider, a pattern consistent with credential dumping via provider changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-08-23Windows cmd.exe Command-Line Anomaly: Missing Spaces Around /c /k /r
Flags cmd.exe invocations with suspicious missing spaces around /c, /k, or /r based on process creation CommandLine patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-08-23Windows Registry Persistence Risk: TypedPaths Key Modified by Non-Explorer Processes
Alerts on changes to Explorer TypedPaths registry entries from processes other than explorer.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh152Free2022-08-22Windows Rundll32 Masquerading: DllRegisterServer CommandLine Not Using rundll32.exe
Alerts when 'DllRegisterServer' appears in the command line while the executing image is not rundll32.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh441Free2022-08-22Windows Command-Line Persistence via TypedPaths Registry Modification
Flags command-line activity referencing the Explorer TypedPaths registry path, which may indicate persistence via registry modification.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium418Free2022-08-22Windows PUA CsExec Execution via Process Creation
Flags Windows process creation of csexec.exe (CsExec) consistent with remote execution tooling usage.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-08-22Windows Process Creation: Uncommon Parent Process Launching link.exe
Alerts when link.exe is spawned with a parent process outside typical Visual Studio paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium367Free2022-08-22Windows Process Creation: Renamed AdFind.exe Executions
Detects renamed AdFind.exe executions using AdFind-style domain discovery command-line indicators, OriginalFileName, and known binary hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2710Free2022-08-21Windows PowerShell Command History Disable via Remove-Module psreadline
Detects PowerShell scripts that remove psreadline with Remove-Module to suppress command history evidence.
Ali Alwashali, Huntrule TeamWindowsps_scriptHigh327Free2022-08-21Windows Script Dropped by Signed Applications and LOLBINs
Detects Windows legitimate/signed executables dropping script files (.ps1, .vbs, .js, etc.) to disk, indicating potential script-based abuse.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh133Free2022-08-21Windows Suspicious App and LOLBIN Dropping Executable Files to Disk
Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh191Free2022-08-21