Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,326 rules
Windows 3CXDesktopApp.exe Beaconing to Suspicious 3CX-Related Domains (Netcon)
Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh189Free2023-03-29Windows DNS: Detect potential beaconing to domains associated with 3CXDesktopApp compromise
Potential Compromised 3CXDesktopApp Beaconing Activity - DNS
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryHigh245Free2023-03-29Windows Process Creation: Sysinternals PsSuspend Targeting msmpeng.exe
Alerts on execution of Sysinternals PsSuspend with command line referencing msmpeng.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh488Free2023-03-23Windows DLL sideloading: iviewers.dll loaded from non-Windows Kits paths
Alerts on unexpected loads of iviewers.dll outside Windows Kits paths, consistent with DLL sideloading attempts.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2023-03-21Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Alerts on successful Azure sign-ins using legacy client user-agent markers that may indicate MFA bypass attempts.
Harjot Singh, '@cyb3rjy0t', Huntrule TeamAzuresigninlogsHigh212Free2023-03-20Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
Alerts on svchost.exe launching rundll32.exe to run davclnt.dll DavSetCookie for WebDav over a non-local IP.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2023-03-16Windows Registry: Hypervisor Enforced Code Integrity Enabled DWORD Set to 0
Alerts when HVCI-related registry values are set to 0, indicating Hypervisor Enforced Code Integrity has been disabled.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsregistry_setHigh141Free2023-03-14Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-03-14Windows Registry Event for Potential Qakbot/IceID Persistence Key
Alerts on Windows registry events referencing a specific \\Software\\firm\\soft\\Name key suffix linked to Qakbot/IceID-like activity.
Hieu Tran, Huntrule TeamWindowsregistry_eventHigh132Free2023-03-13Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
Hieu Tran, Huntrule TeamWindowsprocess_creationHigh91Free2023-03-13Windows Rcdll.dll DLL Sideloading via Image Load Path
Flags rcdll.dll loads from unexpected locations, excluding Visual Studio and Windows Kits directories.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh133Free2023-03-13Windows Process Creation: mshta/VBScript Launching PowerShell and Embedded Backdoor Logic
Alerts on Windows command lines combining mshta VBScript execution bypass, system survey WMI queries, and PowerShell HTTP/Base64 patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2023-03-10Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh197Free2023-03-08Windows sc.exe Service Security Descriptor Changes via sdset
Alerts on sc.exe sdset activity that modifies a service security descriptor to grant access to targeted principals.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2023-02-28Windows Firewall Exception Rule Added for Application in Suspicious Path
Flags new Windows Defender Firewall exception rules for apps located in Temp/PerfLogs/Public/Tasks-like directories.
frack113, Huntrule TeamWindowsfirewall-asHigh81Free2023-02-26