Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,317 rules
Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Flags registry writes to EulaAccepted for Sysinternals-named targets when executed by non-matching image filenames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh70Free2022-08-24Windows msdt.exe Creating Files in Common Startup and Public Directories
Alerts when msdt.exe writes files to high-suspicion directories that may indicate persistence after exploitation.
Vadim Varganov, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh237Free2022-08-24Windows Named Pipe Stream Created with Known Hack Tool IMPHASHs
Alerts on Windows named file stream creation events whose IMPHASH matches common hack-tool binaries.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh122Free2022-08-24Windows CreateStreamHash: Suspicious Downloads From File Sharing and Paste Websites
Identifies Windows stream-hash events tied to downloads from file-sharing/paste domains with Zone-tagged payload extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh60Free2022-08-24Windows Process Creation: Suspicious CLI NetworkProvider Addition for Credential Dumping
Alerts on Windows CLI executions that reference services\... and NetworkProvider, a pattern consistent with credential dumping via provider changes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-08-23Windows cmd.exe Command-Line Anomaly: Missing Spaces Around /c /k /r
Flags cmd.exe invocations with suspicious missing spaces around /c, /k, or /r based on process creation CommandLine patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2022-08-23Windows Registry Persistence Risk: TypedPaths Key Modified by Non-Explorer Processes
Alerts on changes to Explorer TypedPaths registry entries from processes other than explorer.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh152Free2022-08-22Windows Rundll32 Masquerading: DllRegisterServer CommandLine Not Using rundll32.exe
Alerts when 'DllRegisterServer' appears in the command line while the executing image is not rundll32.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh441Free2022-08-22Windows PUA CsExec Execution via Process Creation
Flags Windows process creation of csexec.exe (CsExec) consistent with remote execution tooling usage.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-08-22Windows Process Creation: Renamed AdFind.exe Executions
Detects renamed AdFind.exe executions using AdFind-style domain discovery command-line indicators, OriginalFileName, and known binary hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2710Free2022-08-21Windows PowerShell Command History Disable via Remove-Module psreadline
Detects PowerShell scripts that remove psreadline with Remove-Module to suppress command history evidence.
Ali Alwashali, Huntrule TeamWindowsps_scriptHigh327Free2022-08-21Windows Script Dropped by Signed Applications and LOLBINs
Detects Windows legitimate/signed executables dropping script files (.ps1, .vbs, .js, etc.) to disk, indicating potential script-based abuse.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh143Free2022-08-21Windows Suspicious App and LOLBIN Dropping Executable Files to Disk
Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh191Free2022-08-21Windows Executable Dropping Archive Files via Common LOLBINs and Office Apps
Alerts when Office or other specified Windows binaries create archive files like .zip/.rar/.7z/.diagcab/.appx on disk.
frack113, Florian Roth, Huntrule TeamWindowsfile_eventHigh237Free2022-08-21Windows Process Creation: TruffleSnout.exe Execution
Detects execution of TruffleSnout.exe on Windows using process creation metadata.
frack113, Huntrule TeamWindowsprocess_creationHigh141Free2022-08-20