Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,321 rules
Windows System: Kerberos KDC RC4-HMAC downgrade exploit attempts (CVE-2022-37966)
Identifies Windows Kerberos KDC error events tied to RC4-HMAC downgrade/auth negotiation exploitation behavior (CVE-2022-37966).
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh148Free2022-11-09Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
Tim Rauch, Janantha Marasinghe, Elastic (original idea), Huntrule TeamWindowsprocess_creationHigh142Free2022-11-08Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
Ilya Krestinichev, Huntrule TeamWindowsprocess_creationHigh131Free2022-11-03Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh152Free2022-11-03Linux network connections to ngrok tunneling endpoints
Alerts on Linux connections to ngrok tunnel domains, which may indicate tunneling-based C2 or exfiltration.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionHigh101Free2022-11-03Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh337Free2022-11-01Windows Image Load: Uncommon VSSAPI DLL (vssapi.dll) by Suspicious Executables
Alerts when uncommon processes load vssapi.dll, a Shadow Copy–related DLL, using image load telemetry with path-based exclusions.
frack113, Huntrule TeamWindowsimage_loadHigh80Free2022-10-31Windows Process Command Lines Referencing Dot-Suffixed File Names
Alerts on Windows process executions whose command lines reference file-path strings ending with a dot.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh409Free2022-10-28Windows Exchange PowerShell Cmdlet History Log Files Deleted
Flags deletion of Exchange PowerShell cmdlet history log files in the expected logging directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteHigh171Free2022-10-26Windows: Registry change disabling MacroRuntimeScanScope runtime macro scanning
Flags Office registry updates that set MacroRuntimeScanScope to 0x00000000, disabling runtime scanning for enabled macros.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh1610Free2022-10-25PowerShell: Suspicious Set-Service DACL/SecurityDescriptor Modification for Hidden Services
Flags PowerShell ScriptBlock activity using Set-Service with specific SDDL elements consistent with hiding services from tools like sc.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh82Free2022-10-24Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Alerts when onenote.exe spawns suspicious script or system execution child processes on Windows, consistent with malicious OneNote payload behavior.
Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh60Free2022-10-21Windows Process Creation: Seatbelt.exe PUA Discovery Command-Line Execution
Alerts on Windows process launches of Seatbelt.exe with discovery group arguments and outputfile usage.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh222Free2022-10-18PowerShell Set-Acl targeting Windows folder paths on Windows
Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh90Free2022-10-18