Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,328 rules
Windows Registry Events Targeting SECURITY\Policy\Secrets\ (Snake Malware)
Alerts on Windows registry activity targeting the SECURITY\Policy\Secrets\n registry key suffix.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh379Free2023-05-11Windows File Creation: Non-System WerFault.exe Created in WinSxS
Flags creation of C:\Windows\WinSxS\WerFault.exe by processes outside core Windows system directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh151Free2023-05-10PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh235Free2023-05-09Okta FastPass blocks phishing authentication attempts via MFA
Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.
Austin Songer @austinsonger, Huntrule TeamOktaoktaHigh254Free2023-05-07Windows Wget.exe Downloads From File-Sharing Domains Matching Suspicious Output Flags
Flags wget.exe executions on Windows that download via HTTP from known file-sharing domains and write specific file extensions to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh425Free2023-05-05Windows curl.exe Downloads from File-Sharing Domains with Suspicious Output Extensions
Alerts on curl.exe downloading files over HTTP from file-sharing/content hosting domains, based on process command-line and executable context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-05-05Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh465Free2023-05-05Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh122Free2023-05-04Windows PowerShell Script Block Matching POWERTRASH Behavior Indicators
Detects PowerShell ScriptBlock text containing POWERTRASH-related in-memory and dynamic execution indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2023-05-04PowerShell ScriptBlock Launching wscript.exe via PowerHold-like Code Patterns on Windows
Flags PowerShell ScriptBlock text that writes staged bytes in APPDATA and launches wscript.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh161Free2023-05-04Windows PowerShell Script File Creation Matching FIN7-Style Filenames
Alerts on Windows PowerShell script drops named host_ip.ps1 or ending with _64refl.ps1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh112Free2023-05-04Windows process execution: WerFault.exe launched from WinSxS by services.exe
Alerts on WerFault.exe running from WinSxS when spawned by services.exe on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh177Free2023-05-04Windows Process Creation: Detect jpinst.exe/jpsetup.exe Installation Binary Indicators
Detects execution of jpinst.exe or jpsetup.exe on Windows, indicative of SNAKE installation activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh226Free2023-05-04Windows process command line matches SNAKE installer argument pattern
Alerts on Windows process command lines containing a 64-hex then 16-hex CLI argument sequence consistent with a malware installer pattern.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2023-05-04Windows Service Creation via SCM (Event ID 7045) with svchost.exe and specific service names
Alerts on Windows 7045 service creations where ImagePath contains svchost.exe and service names match Name/msupdate/msupdate2.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh282Free2023-05-02