Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,328 rules
Windows Registry User Profile Creation: ANONYMOUS _DomainUser_ Entries in ProfileList
Alerts on ProfileList registry writes indicating a new user profile with 'ANONYMOUS' and '_DomainUser_' markers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh141Free2023-05-02Windows svchost.exe Loading newdev.dll from AppData Roaming (Potential Persistence)
Alerts on svchost.exe loading newdev.dll from AppData\Roaming, an unusual pattern consistent with stealthy persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh2910Free2023-05-02Windows Process Execution with User Name "ANONYMOUS" from System32 or AppData
Alerts on Windows process executions where the user is marked "ANONYMOUS" and the parent path is in System32 or AppData.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh279Free2023-04-30Windows: Detect newdev.dll created in AppData\Roaming\ starting from C:\Users\
Detects creation of newdev.dll under a user’s AppData\Roaming directory for potential user-scoped persistence.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3610Free2023-04-30Windows File Creation of dllhost.exe in Public Documents Used by COLDSTEEL RAT Variants
Flags creation of C:\users\public\Documents\dllhost.exe on Windows, matching an indicator seen in some COLDSTEEL RAT variants.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-04-30Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh386Free2023-04-27Windows Process Creation Indicators for PowerShell MSI Download and Silent Install (PaperCut MF/NG)
Detects hidden PowerShell downloading a setup.msi and silent msiexec installation tied to PaperCut MF/NG exploitation indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh231Free2023-04-25Linux Python Reverse Shell via pty and socket Module Execution
Alerts on Linux executions of Python -c commands that use socket and pty to connect and spawn a potential reverse shell.
"@d4ns4n_, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"Linuxprocess_creationHigh258Free2023-04-24Windows Application: MSMQ Corrupted Packet (Event ID 2027, Level 2)
Alerts on MSMQ Event ID 2027 (level 2) indicating corrupted packets received by the service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsapplicationHigh162Free2023-04-21Windows: Suspicious child processes spawned by pc-app.exe (PaperCut MF/NG potential exploitation)
Alert on pc-app.exe spawning common command or scripting utilities on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntress DE&TH Team (idea), Huntrule TeamWindowsprocess_creationHigh156Free2023-04-20Windows Log4j/Wstomcat-related Process Execution via ws_tomcatservice.exe Parent
Detects processes spawned by ws_tomcatservice.exe on Windows, excluding repadmin.exe, to surface potential Tomcat exploitation.
Nasreddine Bencherchali (Nextron Systems), MSTIC (idea), Huntrule TeamWindowsprocess_creationHigh393Free2023-04-20Windows RDP client Mstsc.EXE launched from uncommon browser or email parent process
Alerts when mstsc.exe is spawned by a browser or Outlook, suggesting potential RDP access using a local .rdp file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2023-04-18Windows mstsc.exe launched with a local .rdp file from suspicious paths
Alerts on mstsc.exe executions that use a local .rdp file referenced from suspicious command-line paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2023-04-18Windows: Uncommon Process Creates .rdp Remote Desktop File
Alerts on creation of .rdp files by processes that are not typically associated with producing them on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-04-18Windows winget Install from Zone.Identifier/WinGet Temp Contents Marked by Zone Transfer
Alerts on winget staging under Temp\WinGet combined with ZoneTransfer ZoneId=3 and Zone.Identifier ADS contents.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh152Free2023-04-18