Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,513 rules
Windows Registry Seed Value Set Under Cryptography\Providers (Kapeka SIP Persistence)
Flags registry set operations creating/setting a "Seed" value under the Cryptography Providers key path on Windows.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setMedium172Free2024-07-03Windows Registry Run Key Autorun Entries Targeting Kapeka Backdoor
Flags Windows Run key registry changes whose data matches a Kapeka-style rundll32 .wll (#1) autorun entry.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setHigh141Free2024-07-03Kapeka backdoor execution via rundll32.exe with export ordinal #1 and -d on Windows
Flags rundll32.exe command lines launching a Kapeka payload from ProgramData/AppData Local using export ordinal #1 with "-d".
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh289Free2024-07-03Windows Kapeka Backdoor Persistence via schtasks ONSTART or Run Registry Autorun
Flags Windows persistence creation for Kapeka using schtasks (ONSTART) or Run registry entries plus rundll32 ordinal-based execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh514Free2024-07-03Windows: Kapeka backdoor DLL (.wll) loaded via rundll32.exe
Flags rundll32.exe loading a suspicious .wll backdoor from ProgramData or AppData\Local.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh283Free2024-07-03Windows file drop: Kapeka-style decrypted backdoor indicators in AppData with .wll naming
Alerts on suspicious Kapeka backdoor file drops in Windows AppData/Common AppData using .wll naming patterns.
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh496Free2024-07-03Windows Registry: EnablePeriodicBackup value set for periodic system hive backups
Alerts on enabling the Windows registry setting that triggers periodic system hive backups to RegBack on restarts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium182Free2024-07-01Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Flags and image indicators for RemoteKrbRelay execution on Windows, including relaying-related command-line actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2024-06-27Windows File Drop Indicators for RemoteKrbRelay SMB Relay Secret Dump Module
Alerts on creation of RemoteKrbRelay-specific temp files used to stage secrets dump outputs on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh354Free2024-06-27Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule TeamWindowsprocess_creationHigh261Free2024-06-26SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2024-06-26Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh191Free2024-06-26Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.
Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh288Free2024-06-26Detects Unauthenticated Command Injection Attempts Against TP-Link Archer AX21 via Proxy Requests
Alerts on proxy HTTP GET/POST requests targeting Archer AX21 CGI locale/country write parameters consistent with command injection attempts.
Nasreddine Bencherchali (Nextron Systems), Rohit Jain, Huntrule Team—proxyMedium4110Free2024-06-25Windows Process Execution: LaZagne Credential Dumping Utility (lazagne.exe)
Flags Windows process launches consistent with running LaZagne (lazagne.exe) for credential and password recovery.
Nasreddine Bencherchali, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium173Free2024-06-24