Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Creation: reg.exe Modifying Group Policy Registry Settings
Flags reg.exe commands targeting Group Policy System registry settings related to security and policy refresh.
frack113, Huntrule TeamWindowsprocess_creationMedium71Free2022-08-19Windows PresentationHost.EXE downloading files via URL in command line
Flags PresentationHost.EXE executions whose command line includes http/https/ftp URLs, indicating potential arbitrary file downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium142Free2022-08-19Windows: MSPUB.EXE Downloading Arbitrary Files via HTTP/FTP URIs
Flags MSPUB.EXE executions with HTTP/FTP URLs that may indicate arbitrary file downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3610Free2022-08-19Windows: MSOHTMED.EXE Arbitrary File Download Using HTTP/FTP URLs
Alerts when MSOHTMED.EXE is executed with HTTP/FTP URLs to download an arbitrary file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2022-08-19Windows Register_app.vbs Proxy COM+ Provider Registration via Process Command-Line
Alerts when REGISTER_APP.VBS is executed with -register to register a VSS/VDS provider as a COM+ application.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2022-08-19Windows: Launch-VsDevShell.ps1 Proxy Execution via Process Command Line
Detects command-line usage of Launch-VsDevShell.ps1 with Visual Studio path flags on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium101Free2022-08-19Windows InstallUtil.exe Downloading Files via HTTP/FTP
Flags InstallUtil.exe execution with http/https/ftp URLs indicative of remote file downloads on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium82Free2022-08-19Windows DeviceCredentialDeployment.exe Execution for Process Stealth (T1218)
Flags Windows process execution when DeviceCredentialDeployment.exe starts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium167Free2022-08-19Windows: Suspicious CustomShellHost.exe execution spawned by non-Explorer parent
Alerts on CustomShellHost.exe executions where explorer.exe is not the expected parent process image.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-08-19Windows PowerShell: GPO ScriptBlock Modifying Group Policy and SmartScreen Settings
Alerts on PowerShell ScriptBlock content referencing Group Policy policy keys and specific security policy value names.
frack113, Huntrule TeamWindowsps_scriptMedium259Free2022-08-19Windows Process Execution of HandleKatz LSASS Dumper (loader.exe)
Flags HandleKatz-style loader.exe executions that dump LSASS into obfuscated .obf files using --pid and --outfile.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2022-08-18Windows driver load of HackSys Extreme Vulnerable Driver (HEVD.sys) via image hash
Flags Windows systems when HEVD driver \HEVD.sys is loaded with known IMPHASH values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh2110Free2022-08-18Windows Malicious Driver Load by Known Hashes
Alerts on Windows driver loads matching known malicious driver hashes (MD5/SHA1/SHA256/IMPHASH).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh374Free2022-08-18Windows Executable Connections to Dead Drop Resolver Domains Excluding Common Browsers
Flags non-browser Windows executables making outbound connections to known dead-drop resolver domain patterns.
Sorina Ionescu, X__Junior (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh403Free2022-08-17Windows DLL sideloading via third-party application directories (ImageLoad event)
Flags Windows ImageLoad events for specific DLL sideloading candidates tied to Lenovo and Toshiba software.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium101Free2022-08-17