Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,433 rules
Windows: Detect Odbcconf.exe INSTALLDRIVER DLL Installation via Process Command Line
Alerts when odbcconf.exe is run with INSTALLDRIVER and a .dll, indicating potential malicious ODBC driver DLL installation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-05-22Windows Suspicious Non-Browser Network Traffic to api.telegram.org
Alerts on Windows network connections to api.telegram.org by processes other than common web browsers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium131Free2023-05-19Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters
Flags Windows Event 4661 activity indicating password policy enumeration (ReadPasswordParameters on Security Account Manager).
Zach Mathis, Huntrule TeamWindowssecurityMedium167Free2023-05-19Windows Registry Run Key Persistence Using Small Sieve Typo Value Strings
Flags registry Run-key writes on Windows with Small Sieve-specific typo and executable detail strings in value data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh178Free2023-05-19Proxy HTTP GET to api.telegram.org with chat_id and text com/ (Small Sieve C2 behavior)
Alerts on proxy HTTP GET requests to api.telegram.org containing a specific chat_id and com/ prefix consistent with C2 behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyCritical132Free2023-05-19Windows Process Creation: Detects Command-Line Ending With '.exe Platypus'
Alerts when a Windows process command line ends with '.exe Platypus', matching a Small Sieve indicator.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh341Free2023-05-19Windows: Small Sieve IoC File Creation via AppData and Typo Filename Indicators
Alerts on Windows file events with Small Sieve filename typo/path indicators or the OutlookDataPlus.txt IOCs.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh113Free2023-05-19Windows WerFault ReflectDebugger Registry Key Value Targeting
Flags registry set events targeting WerFault ReflectDebugger under Windows Error Reporting Hangs for potential persistence abuse.
X__Junior, Huntrule TeamWindowsregistry_setHigh141Free2023-05-18PowerShell Certificate Export Cmdlets in Windows Process Creation
Flags PowerShell command lines invoking certificate export cmdlets (Export-PfxCertificate/Export-Certificate) on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium428Free2023-05-18Windows WWlib.DLL sideloading via Office process loading behavior
Alert on Windows image-load events where winword-associated processes load wwlib.dll outside expected Office paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium203Free2023-05-18Windows CreateStreamHash: Suspicious Embedded File Download Indicators via .zip TLD
Flags Windows downloads indicating .zip/ plus ':Zone' in target filenames for risky executable or script extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh162Free2023-05-18Windows Process Creation: findstr.exe Searches for 'passwords' Keywords in Multiple Languages
Flags findstr.exe command lines searching password keywords across multiple languages.
Josh Nickels, Huntrule TeamWindowsprocess_creationMedium70Free2023-05-18Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments
Flags rundll32.exe launches with command-line ordinal obfuscation patterns.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2023-05-17Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2023-05-17Windows Process Creation: cloudflared Tunnel Execution with Config and Credentials Flags
Alerts on Windows processes running cloudflared tunnels with config and token/credential flags.
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium361Free2023-05-17