Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,315 rules
Windows Process Execution of HandleKatz LSASS Dumper (loader.exe)
Flags HandleKatz-style loader.exe executions that dump LSASS into obfuscated .obf files using --pid and --outfile.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2022-08-18Windows driver load of HackSys Extreme Vulnerable Driver (HEVD.sys) via image hash
Flags Windows systems when HEVD driver \HEVD.sys is loaded with known IMPHASH values.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh2110Free2022-08-18Windows Malicious Driver Load by Known Hashes
Alerts on Windows driver loads matching known malicious driver hashes (MD5/SHA1/SHA256/IMPHASH).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh374Free2022-08-18Windows Executable Connections to Dead Drop Resolver Domains Excluding Common Browsers
Flags non-browser Windows executables making outbound connections to known dead-drop resolver domain patterns.
Sorina Ionescu, X__Junior (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh403Free2022-08-17Windows: Detect Microsoft Office DLL sideloading via ImageLoad of outllib.dll from nonstandard path
Alerts on outllib.dll loads from non-standard locations rather than typical Microsoft Office directories.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadHigh113Free2022-08-17Sysmon FileBlockExecutable event: blocked executable execution attempts on Windows
Alerts when Sysmon blocks an attempted executable execution due to FileBlockExecutable policy violations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssysmonHigh4610Free2022-08-16Windows Process Creation: mshtml.dll RunHTMLApplication Execution via Protocol Handlers
Alerts on Windows command lines invoking mshtml.dll RunHTMLApplication (via #135) with path traversal markers.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Josh Nickels, frack113, Zaw Min Htun (ZETA), Huntrule TeamWindowsprocess_creationHigh251Free2022-08-14Windows DLL Sideloading: System DLL Names Loaded from Non-Standard Paths (ImageLoad)
Alerts when Windows image loads DLL names typically found in system locations, excluding common benign paths to reduce false positives.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh1910Free2022-08-14Windows rundll32 Loading Renamed comsvcs.dll via DLL Image Load
Flags rundll32.exe loading a renamed comsvcs.dll module consistent with process memory dumping behavior on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh163Free2022-08-14Windows: Unusual Process Tree for wab.exe and wabmig.exe
Alert on abnormal parent/child process relationships involving wab.exe and wabmig.exe in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh202Free2022-08-12Windows Process Creation: wab.exe or wabmig.exe Run from Non-Default Paths
Alerts when wab.exe or wabmig.exe run from unexpected directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh198Free2022-08-12Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2022-08-12Windows file write events where executables save files with suspicious script/binary extensions
Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2022-08-12Windows Malicious iphlpapi.dll Dropped in OneDrive/Teams AppData Directory
Flags creation of iphlpapi.dll in the Microsoft AppData area used by OneDrive/Teams, consistent with DLL sideloading attempts.
frack113, Huntrule TeamWindowsfile_eventHigh121Free2022-08-12Webserver URI Probe for Workspace ONE Access Auth Bypass Attempt (CVE-2022-31656)
Alerts on webserver requests to Workspace ONE Access containing a URI query pattern linked to CVE-2022-31656 exploitation.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh239Free2022-08-12