Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry: OneDriveStandaloneUpdater.exe URL From UpdateOfficeConfig for Proxy Download
Alerts on registry settings that redirect OneDrive update URL retrieval from UpdateOfficeConfig for internet downloads.
frack113, Huntrule TeamWindowsregistry_setHigh188Free2022-05-28PowerShell: Signed UtilityFunctions.ps1 Loading Managed DLL via Proxy Execution
Flags PowerShell command lines referencing UtilityFunctions.ps1 with RegSnapin usage consistent with managed DLL proxy execution.
frack113, Huntrule TeamWindowsprocess_creationMedium121Free2022-05-28Windows: Pubprn.vbs Script Proxy Execution via script: Command Line
Flags command-line executions referencing Pubprn.vbs with 'script:' indicative of proxy script command execution on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium152Free2022-05-28Windows PowerShell detects obfuscated Net.Webclient casing anomalies in command line
Alerts when PowerShell command lines contain encoded obfuscation patterns referencing Net.Webclient with anomalous casing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh229Free2022-05-24Windows PowerShell Process Command Lines With Encoded Command Flags
Alerts on PowerShell (pwsh) command lines using encoded command flags and encoded-looking substrings, excluding gc_worker.exe-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-05-24Windows: Jlaive In-Memory Assembly Execution via Copied Batch Executable
Detects chained cmd/.bat staging that uses xcopy plus PowerShell/pwsh and attrib +h/+s to run a .bat.exe payload associated with Jlaive.
Jose Luis Sanchez Martinez (@Joseliyo_Jstnk), Huntrule TeamWindowsprocess_creationMedium153Free2022-05-24Windows: rundll32.exe launched by explorer.exe parent process
Alerts when explorer.exe spawns rundll32.exe with specific command-line characteristics on Windows.
CD_ROM_, Huntrule TeamWindowsprocess_creationMedium205Free2022-05-21Windows PowerShell Script Proxy Execution via CL_mutexverifiers.ps1
Alerts on PowerShell being launched with CL_mutexverifiers that proxies additional script execution.
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, frack113, Huntrule TeamWindowsprocess_creationMedium60Free2022-05-21PowerShell Assembly Loading via CL_LoadAssembly.ps1 Functions
Alerts on PowerShell command lines that call LoadAssemblyFromPath/LoadAssemblyFromNS in CL_LoadAssembly.ps1 context.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2022-05-21Windows AnyDesk Executed from Suspicious Directory
Alerts on AnyDesk execution from non-standard folders on Windows, indicating potential remote access abuse.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh318Free2022-05-20Windows PowerShell Base64 Encoded Commands Containing Invoke- ( -e )
Flags PowerShell executions using the -e encoded command flag with Base64 patterns consistent with an Invoke- call.
pH-T (Nextron Systems), Harjot Singh, @cyb3rjy0t, Huntrule TeamWindowsprocess_creationHigh131Free2022-05-20Windows grpconv Utility Execution with Output Option
Alerts on Windows process command lines invoking GrpConv with -o, potentially for .grp conversion or persistence.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-05-19Windows Office Applications Downloading Files via HTTP/HTTPS
Detects Office binaries invoked with command lines containing http/https, indicating potential arbitrary file download.
Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationHigh71Free2022-05-17Windows Event Log Cleared (EventID 104, Microsoft-Windows-Eventlog)
Alerts when Microsoft-Windows-Eventlog reports Event ID 104 for core event log channels, indicating log clearing.
Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh376Free2022-05-17Windows: Process creation of TTDInject.exe (ttdinject.exe) for Time Travel Debugging
Alerts on Windows process creation for ttdinject.exe (TTDInject.EXE), a time travel debugging component.
frack113, Huntrule TeamWindowsprocess_creationMedium152Free2022-05-16