Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,358 rules
AWS CloudTrail: Instance Profile Role Assumed Actions Outside SSM RegisterManagedInstance
Identifies CloudTrail activity from assumed-role instance identities when it is not part of SSM RegisterManagedInstance.
jamesc-grafana, Huntrule TeamAwscloudtrailHigh153Free2024-07-11Windows: Detect regedit.exe creating a PDF file
Alerts when RegEdit.exe creates a .pdf file on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh326Free2024-07-08Windows Registry: DisableHypervisorEnforcedPagingTranslation Set to 1
Alerts when Windows disables Hypervisor Enforced Paging Translation by setting DisableHypervisorEnforcedPagingTranslation to 1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2024-07-05Windows Security Event 4698: Kapeka-like Scheduled Task Creation
Flags suspicious Kapeka-like scheduled task creation via Event 4698 using TaskContent paths, rundll32/.wll command markers, and OneDrive/Sens Api task names.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowssecurityHigh338Free2024-07-03Windows Registry Run Key Autorun Entries Targeting Kapeka Backdoor
Flags Windows Run key registry changes whose data matches a Kapeka-style rundll32 .wll (#1) autorun entry.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setHigh141Free2024-07-03Kapeka backdoor execution via rundll32.exe with export ordinal #1 and -d on Windows
Flags rundll32.exe command lines launching a Kapeka payload from ProgramData/AppData Local using export ordinal #1 with "-d".
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh289Free2024-07-03Windows Kapeka Backdoor Persistence via schtasks ONSTART or Run Registry Autorun
Flags Windows persistence creation for Kapeka using schtasks (ONSTART) or Run registry entries plus rundll32 ordinal-based execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh514Free2024-07-03Windows: Kapeka backdoor DLL (.wll) loaded via rundll32.exe
Flags rundll32.exe loading a suspicious .wll backdoor from ProgramData or AppData\Local.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh283Free2024-07-03Windows file drop: Kapeka-style decrypted backdoor indicators in AppData with .wll naming
Alerts on suspicious Kapeka backdoor file drops in Windows AppData/Common AppData using .wll naming patterns.
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh496Free2024-07-03Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Flags and image indicators for RemoteKrbRelay execution on Windows, including relaying-related command-line actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2024-06-27Windows File Drop Indicators for RemoteKrbRelay SMB Relay Secret Dump Module
Alerts on creation of RemoteKrbRelay-specific temp files used to stage secrets dump outputs on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh354Free2024-06-27Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule TeamWindowsprocess_creationHigh261Free2024-06-26SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2024-06-26Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh191Free2024-06-26Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.
Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh288Free2024-06-26