Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,331 rules
Suspicious Child Process of aspnet_compiler.exe on Windows
Alerts when aspnet_compiler.exe spawns calc/notepad or executes from public/temp/Task-related paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh418Free2023-08-14Windows DLL sideloading via unsigned mfdetours.dll loaded by image_load
Alerts on loading unsigned \mfdetours.dll, consistent with DLL sideloading abuse via mftrace.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh60Free2023-08-11Windows Process Creation: Execution of Renamed gpg.exe or gpg2.exe
Alerts on Windows executions of renamed gpg.exe/gpg2.exe using process creation telemetry.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh178Free2023-08-09Windows Provisioning Registry Key Abuse Leading to Indirect Execution via Provlaunch.exe
Flags Windows command lines referencing the provisioning commands registry path commonly abused for Provlaunch.exe-based indirect execution.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh3510Free2023-08-08Windows: Alert on Suspicious Child Processes Spawned by provlaunch.exe
Detects provlaunch.exe launching suspicious child executables and processes from common temp/task paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh212Free2023-08-08Azure risk detection: anomalousToken risk events
Flags Azure Entra ID risk events indicating anomalous token lifetime or use from unfamiliar locations.
Mark Morowczynski '@markmorow', Huntrule TeamAzureriskdetectionHigh122Free2023-08-07Windows Browser-Injected rundll32 Execution Indicative of GuLoader Activity
Flags rundll32.exe being launched from a browser process, matching GuLoader-style injected browser execution behavior on Windows.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh376Free2023-08-07Windows ImageLoad DLL Sideloading: EACore.dll
Alerts on Windows loading of EACore.dll that may indicate DLL sideloading, excluding a specific EA Desktop legitimate case.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh102Free2023-08-03Windows Registry Key Abuse via Provisioning Commands for Proxy Binary Execution
Flags registry modifications to the Provisioning Commands key path that may enable indirect execution via Provlaunch.exe.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setHigh81Free2023-08-02Windows AppCompatFlags InstalledSDB New Shim Database in Non-Default Path
Flags persistence attempts where a shim database is registered via InstalledSDB with a non-default DatabasePath on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh124Free2023-08-01Windows Registry: New AppCompatFlags custom shim databases targeting system processes
Alerts on Windows registry writes to AppCompatFlags Custom shim paths targeting common system processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh303Free2023-08-01Windows VMMap Loading Unsigned dbghelp.dll from C:\Debuggers\dbghelp.dll
Alerts when VMMap loads an unsigned dbghelp.dll from C:\Debuggers, suggesting DLL sideloading on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh122Free2023-07-28Windows CreateRemoteThread in mstsc.exe From Suspicious Source Paths
Alerts when mstsc.exe creates remote threads from processes running out of common suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_remote_threadHigh249Free2023-07-28Windows: Alert on wget.exe downloading files from an IP with output flags
Flags Windows wget.exe usage to download HTTP URLs from IPs and write outputs to script/binary extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3510Free2023-07-27Suspicious curl.exe File Downloads From Direct IP Addresses on Windows
Alerts on Windows curl.exe commands downloading from an IP address with HTTP/S and suspect file extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2023-07-27