Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,331 rules
Sysmon FileBlockShredding Policy Violations (Event ID 28) on Windows
Alerts on Sysmon Event ID 28 when file shredding is blocked by the configured shredding policy on Windows.
frack113, Huntrule TeamWindowssysmonHigh407Free2023-07-20Windows: Detect Cmd.exe Redirection of Discovery Commands by Ursnif
Flags explorer-launched cmd.exe commands that use /C and redirect output to AppData local temp .bin files.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh366Free2023-07-16Windows PowerShell WMI Win32_NTEventlogFile Calls with Event Log Tampering Methods
Flags PowerShell calling Win32_NTEventlogFile WMI methods commonly used to clear, delete, backup, or alter Windows event logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2023-07-13Windows Security 5140 File Share Access to MSHTML_C7 IP-Named Paths
Alerts on Windows file share access events targeting \MSHTML_C7\ shares with an IP-like naming pattern (EventID 5140).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh132Free2023-07-13Windows Process Creation From Fake Recycle.Bin Directories
Alerts on Windows processes launched from fake RECYCLER.BIN / RECYCLERS.BIN folder paths often used for stealth.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh329Free2023-07-12Windows: Suspicious File Creation in Fake RECYCLER.BIN Staging Folders
Alerts on Windows file writes involving RECYCLERS.BIN\ or RECYCLER.BIN\ paths often used for staging.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh408Free2023-07-12HTTP GET Requests Containing /MSHTML_C7/ URL Marker (Proxy Logs)
Alerts on proxy HTTP GET requests whose URI contains /MSHTML_C7/.
X__Junior, Huntrule Team—proxyHigh123Free2023-07-12Proxy GET Requests with IP-Embedded CVE-Related URL Parameters
Finds proxy GET URIs with risky extensions and a d=IPv4 parameter value in the query string.
X__Junior, Huntrule Team—proxyHigh431Free2023-07-12Windows DLL Sideloading via Abusable DLLs Loaded from Suspicious Locations
Flags Windows module loads of specific abusable DLL names from public, temp, or user folders consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh445Free2023-07-11Windows PowerShell Decryption-Like Activity Involving .LNK File Processing
Identifies PowerShell runs that enumerate and process *.lnk content using byte-level reads/writes consistent with decryption staging.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2023-06-30Windows Registry: Uncommon Microsoft Office Trusted Location Path Added
Alerts on registry changes adding non-standard Microsoft Office Trusted Location paths that could undermine macro security.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2023-06-21Windows Registry TrustRecords Change for Macro-Enabled Documents in Suspicious Paths
Alert on Windows registry changes to Office TrustRecords where trusted-document paths fall in suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh131Free2023-06-21Windows: Office Executable Running a Document from Trusted Template/Startup Paths
Alerts when Office apps are launched with command lines pointing to documents under Office template/Startup paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2023-06-21Windows DLL side-loading via appverifUI.dll image loads
Alerts when appverifUI.dll is loaded on Windows from unexpected paths, a common DLL sideloading technique.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh214Free2023-06-20Windows Security 4719: Important Audit Policy Categories Disabled
Alerts on Windows Security 4719 indicating auditing was disabled for important security event subcategories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh186Free2023-06-20