Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,320 rules
Windows schtasks.exe Used to Delete Scheduled Tasks for System and Security Components
Alerts when schtasks.exe runs with /delete targeting sensitive Windows scheduled tasks that support security, updates, or recovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4210Free2022-09-09Windows vmnat.exe Renamed Execution for Possible DLL Side-Loading
Alerts on Windows processes where vmnat.exe appears renamed, which may support stealthy execution and DLL side-loading behavior.
elhoim, Huntrule TeamWindowsprocess_creationHigh103Free2022-09-09Windows Root Certificate Installation from Suspicious Paths via PowerShell Import-Certificate
Alerts on PowerShell importing a root certificate into Cert:\LocalMachine\Root from suspicious file paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-09-09PowerShell Email Address Exfiltration via EXIF-style Recipient Harvesting on Windows
Alerts when PowerShell command lines enumerate Exchange recipients and expand email address properties, indicating potential email data exfiltration.
Nasreddine Bencherchali (Nextron Systems), Azure-Sentinel (idea), Huntrule TeamWindowsprocess_creationHigh91Free2022-09-09Windows node.exe Execution with -e/--eval and suspicious child process usage
Alerts on node.exe started with -e/--eval and command-line indicators of child_process and net.socket connect activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh182Free2022-09-09Windows Process Creation: SharpEvtMute Execution (Event Log Tampering)
Alerts on SharpEvtMute.exe runs with event-log filter and encoded command-line parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2022-09-07Windows SysmonEnte Process Access Attempt (Sysmon.exe/ Sysmon64.exe/ Sysmon64a.exe)
Flags attempts to access Sysmon binaries consistent with SysmonEnte execution based on TargetImage, GrantedAccess, and CallTrace.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh435Free2022-09-07Windows: Detect EvtMuteHook.dll Load by IMPHASH Match (SharpEvtMute)
Detects DLL loads with a specific IMPHASH consistent with EvtMuteHook.dll used for event log tampering.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadHigh92Free2022-09-07Windows suspicious file download URLs using direct IP address with script/binary extensions
Alerts on Windows downloads from HTTP/HTTPS direct IP URLs targeting script/binary/shortcut-like filenames.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh113Free2022-09-07Windows Process Creation: WinAPI Function Names in Command-Line
Alerts on Windows processes whose command lines reference WinAPI functions/modules commonly used for dynamic invocation and memory/process manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-06Windows Process Creation: Renamed Sysinternals Sdelete Execution
Alerts on Windows processes created with OriginalFileName sdelete.exe but executed via renamed sdelete binary paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-09-06Windows SharpChisel Command-Line Execution via SharpChisel.exe
Alerts on Windows process executions where the SharpChisel executable or Product metadata indicates SharpChisel.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2022-09-05Windows: Detect QuarksPwDump.exe Credential Dumping via Command-Line Parameters
Flags QuarksPwDump.exe executions on Windows that attempt local/domain hash and related data dumping.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-09-05Windows File Events: Suspicious Executable File Name Creation
Alerts on Windows file creation with suspicious executable filename patterns, including .bat.exe/.sys.exe and deceptive path-based names.
frack113, Huntrule TeamWindowsfile_eventHigh202Free2022-09-05Windows Registry Tampering Targeting Sophos AV Tamper Protection Enabled Flags
Flags Windows registry changes that disable Sophos AV tamper protection by clearing specific enabled DWORD values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh218Free2022-09-02