Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Detect Microsoft Office DLL sideloading via ImageLoad of outllib.dll from nonstandard path
Alerts on outllib.dll loads from non-standard locations rather than typical Microsoft Office directories.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadHigh113Free2022-08-17Windows Chrome Frame Helper DLL Sideloading via Image Load
Alerts when chrome_frame_helper.dll loads from an unexpected location on Windows, indicating possible DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium3810Free2022-08-17Windows DLL Sideloading Using Antivirus/Vendor DLLs Based on Loaded Image Names
Alerts on suspicious DLL loads matching known antivirus/security component DLL names when not from expected vendor paths.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium323Free2022-08-17Zimbra web server: Unauthenticated RCE probing via mboximport POST requests
Alerts on unauthenticated-style Zimbra POST activity targeting the mboximport servlet with RCE-related query parameters.
"@gott_cyber, Huntrule Team"—webserverMedium189Free2022-08-17Sysmon FileBlockExecutable event: blocked executable execution attempts on Windows
Alerts when Sysmon blocks an attempted executable execution due to FileBlockExecutable policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssysmonHigh4610Free2022-08-16PowerShell Write-EventLog with -RawData Flag
Alerts when PowerShell script blocks call Write-EventLog using the -RawData flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium133Free2022-08-16Windows: User Profiles Service EventID 1511 indicating potential CVE-2022-21919 or CVE-2021-34484 LPE
Alerts on User Profiles Service Event ID 1511, a possible signal of LPE exploitation attempts associated with CVE-2022-21919 or CVE-2021-34484.
Cybex, Huntrule TeamWindowsapplicationLow336Free2022-08-16Windows Process Creation: mshtml.dll RunHTMLApplication Execution via Protocol Handlers
Alerts on Windows command lines invoking mshtml.dll RunHTMLApplication (via #135) with path traversal markers.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Josh Nickels, frack113, Zaw Min Htun (ZETA), Huntrule TeamWindowsprocess_creationHigh251Free2022-08-14Windows Firewall rule deleted via netsh.exe command line
Flags netsh.exe executions that contain Windows Firewall rule deletion commands.
frack113, Huntrule TeamWindowsprocess_creationMedium113Free2022-08-14Windows DLL Sideloading: System DLL Names Loaded from Non-Standard Paths (ImageLoad)
Alerts when Windows image loads DLL names typically found in system locations, excluding common benign paths to reduce false positives.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh1910Free2022-08-14Windows rundll32 Loading Renamed comsvcs.dll via DLL Image Load
Flags rundll32.exe loading a renamed comsvcs.dll module consistent with process memory dumping behavior on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2022-08-14Windows Shell-Core: Installed Application Shortcut Indicators for Known Tools
Flags suspicious installation-style activity in Windows shell-core based on EventID 28115 app resolver cache entries for specific tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsshell-coreMedium427Free2022-08-14Windows: Detect ESENT New Database Created with ntds.dit Written to Suspicious Path
Identifies ESENT EventID 325 where a new database containing ntds.dit is created in suspicious locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium90Free2022-08-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationMedium100Free2022-08-14PUA Tool Update Check to /checkupdate.php (Advanced IP/Port Scanner) via Proxy
Identifies proxy HTTP requests to /checkupdate.php from Advanced IP/Port Scanner with expected update-check query parameters.
Axel Olsson, Huntrule TeamWebproxyMedium143Free2022-08-14