Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,523 rules
Windows MMC Loads Script Engine DLLs (vbscript.dll, jscript.dll, jscript9.dll)
Alerts when mmc.exe loads vbscript/jscript script engine DLLs, which can indicate script execution in a trusted process.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadMedium504Free2025-02-05Windows file creation of executable/script files in \Users\Public
Alerts on Windows file creation in \Users\Public\ with potentially malicious script/binary extensions.
The DFIR Report, Huntrule TeamWindowsfile_eventHigh183Free2025-01-23Windows: Clfs.sys Loaded from Suspicious Process Image Paths
Alerts when clfs.sys is loaded by a process running from user/temp/perflogs-style suspicious paths on Windows.
X__Junior, Huntrule TeamWindowsimage_loadMedium272Free2025-01-20Linux: Shell spawned by rsync without -e flag in command line
Flags rsync/rsyncd spawning a shell when rsync lacks the expected " -e " command-line flag.
Florian Roth, Huntrule TeamLinuxprocess_creationHigh424Free2025-01-18Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Detects registry changes to Windows Event Log ChannelAccess SDDL, which can limit event log visibility or control.
X__Junior, Huntrule TeamWindowsregistry_setHigh181Free2025-01-16M365 Audit: Successful Intune Company Portal login via Cmsi
Flags successful Company Portal (Intune) logins via Cmsi audit events that may indicate Conditional Access bypass attempts.
Josh Nickels, Marius Rothenbücher, Huntrule TeamM365auditHigh472Free2025-01-08Windows Application Error 1000 with lsass.exe and WLDAP32.dll Indicating LDAP Nightmare Attempt (CVE-2024-49113)
Alerts on Windows Application Error (EventID 1000) showing lsass.exe crashing in WLDAP32.dll—potential CVE-2024-49113 exploitation attempt.
Samuel Monsempes, Huntrule TeamWindowsapplicationHigh153Free2025-01-08Windows Process Creation: Microsoft QuickAssist.exe Execution
Alerts on execution of QuickAssist.exe by matching the process image ending with \QuickAssist.exe.
Muhammad Faisal (@faisalusuf), Huntrule TeamWindowsprocess_creationLow151Free2024-12-19Windows DNS Queries Initiated by QuickAssist.exe to remoteassistance.support.services.microsoft.com
Alerts when QuickAssist.exe performs DNS lookups for the Microsoft Quick Assist remote session endpoint.
Muhammad Faisal (@faisalusuf), Huntrule TeamWindowsdns_queryLow489Free2024-12-19AWS CloudTrail: CreateFunctionUrlConfig Indicates Lambda Function URL Added
Flags when a Lambda Function URL configuration is created via the CreateFunctionUrlConfig API call.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium162Free2024-12-19AWS EC2 ImportKeyPair Activity Monitoring (CloudTrail)
Flags CloudTrail EC2 ImportKeyPair events that may indicate newly imported SSH key access setup.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium101Free2024-12-19AWS IAM SAML Provider Deletion via CloudTrail
Alerts on successful CloudTrail events where an AWS SAML provider is deleted, signaling potential disruption of admin/security access.
Ivan Saakov, Huntrule TeamAwscloudtrailMedium1910Free2024-12-19Windows Process Creation: Execution of vbc.exe Spawned from more.com
Alerts when more.com starts vbc.exe on Windows, matching a known stealer execution pattern.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationHigh141Free2024-12-19Windows File Creation to Roaming AppData DataLogs.conf and RAT-Client Names
Alerts on creation of specific RAT client config files under AppData\Roaming on Windows.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_eventHigh317Free2024-12-19Windows Process Creation: Suspicious cmd.exe Launch with Encoded PowerShell from Cleo Suite
Alerts on cmd.exe launching PowerShell encoded commands from Cleo javaw.exe components with .Download.
Tanner Filip, Austin Worline, Chad Hudson, Matt Anderson, Huntrule TeamWindowsprocess_creationHigh327Free2024-12-09