Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,329 rules
Windows rundll32.exe Execution via cmd/cscript/powershell with .dll and Suspicious Directories
Alerts on rundll32.exe execution with DLL arguments from common Windows script/LOLBins and suspicious staging paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-05-24Windows Registry: New ODBC Driver Registration in Suspicious Path
Alerts when Windows registers a new ODBC driver under the ODBCINST.INI area with details pointing to suspicious filesystem paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh266Free2023-05-23Windows: Odbcconf.EXE INSTALLDRIVER Use With Missing .dll Target
Flags odbcconf.exe running INSTALLDRIVER when the driver argument lacks a .dll extension.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-05-23Windows: BlueSky ransomware-related file and share access events
Alerts on Windows file/share access involving .bluesky and "DECRYPT FILES BLUESKY" artifact naming tied to BlueSky activity.
j4son, Huntrule TeamWindowssecurityHigh161Free2023-05-23Windows Process Execution of Odbcconf.exe with -f Response File Flag
Alerts on Odbcconf.exe being run with -f to load a response file, excluding runonce-driven executions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2023-05-22Windows: Suspicious Odbcconf.EXE REGSVR usage with non-DLL-suffixed target
Flags odbcconf.exe launched with REGSVR while the target lacks a .dll extension on Windows process creation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh453Free2023-05-22Windows Process Execution: odbcconf.exe with DLL in Suspicious Path
Flags odbcconf.exe process launches when the command line references DLL-related paths in suspicious Windows locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2023-05-22Windows Registry Run Key Persistence Using Small Sieve Typo Value Strings
Flags registry Run-key writes on Windows with Small Sieve-specific typo and executable detail strings in value data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh178Free2023-05-19Windows Process Creation: Detects Command-Line Ending With '.exe Platypus'
Alerts when a Windows process command line ends with '.exe Platypus', matching a Small Sieve indicator.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh341Free2023-05-19Windows: Small Sieve IoC File Creation via AppData and Typo Filename Indicators
Alerts on Windows file events with Small Sieve filename typo/path indicators or the OutlookDataPlus.txt IOCs.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh113Free2023-05-19Windows WerFault ReflectDebugger Registry Key Value Targeting
Flags registry set events targeting WerFault ReflectDebugger under Windows Error Reporting Hangs for potential persistence abuse.
X__Junior, Huntrule TeamWindowsregistry_setHigh141Free2023-05-18Windows CreateStreamHash: Suspicious Embedded File Download Indicators via .zip TLD
Flags Windows downloads indicating .zip/ plus ':Zone' in target filenames for risky executable or script extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh162Free2023-05-18Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2023-05-17AWS CloudTrail: S3 Browser Creates IAM User or Access Key
Alerts on CloudTrail IAM CreateUser/CreateAccessKey actions initiated by a "S3 Browser" user agent.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh131Free2023-05-17AWS CloudTrail: S3 Browser creates inline IAM policy with default bucket placeholder
Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh123Free2023-05-17