Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,432 rules
Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions
Alert on certutil.exe -encode activity that targets files with suspicious extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh140Free2023-05-15Windows DLL Sideloading: goopdate.dll Loaded from Nonstandard Paths
Alerts when goopdate.dll is loaded from non-standard locations, suggesting possible DLL sideloading behavior on Windows.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium443Free2023-05-15Windows Process Creation: SolidPDFCreator.dll Copy and Run Key Persistence Indicators
Flags Windows command lines that copy SolidPDFCreator.dll and set a Run registry key for auto-execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2023-05-15Windows Service Creation for Backdoor Persistence via GoogleUpdate (Event ID 7045)
Flags creation of a "GoogleUpdate" Windows service with rundll32/FileProtocolHandler image path pointing to ProgramData persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemCritical504Free2023-05-15Windows: GoogleUpdate.exe Self-Spawn From Uncommon Path
Alerts when GoogleUpdate.exe launches another GoogleUpdate.exe from an unusual directory.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2023-05-15Windows Devil Bait-like Recon via Wscript/Cmd with APPDATA Redirection
Flags cmd.exe launched by wscript.exe to redirect discovery output into %APPDATA%\Microsoft (.xml/.txt) using system enumeration commands.
Nasreddine Bencherchali (Nextron Systems), NCSC (Idea), Huntrule TeamWindowsprocess_creationHigh2310Free2023-05-15Uncommon Windows Processes Writing .txt/.xml in AppData\Roaming\Microsoft
Flags creation of .txt/.xml files in AppData\Roaming\Microsoft by schtasks.exe, wscript.exe, or mshta.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-05-15Windows RoboForm DLL Sideloading via ImageLoaded roboform.dll/roboform-x64.dll
Alerts on loaded roboform*.dll modules on Windows when module loading is not matched to expected RoboForm binaries.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium447Free2023-05-14Potential C2 HTTP Traffic via Goofy Guineapig User-Agent to static.tcplog.com (Proxy Logs)
Flags proxy HTTP requests with a specific Chrome-like User-Agent to static.tcplog.com, consistent with potential C2 traffic.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh161Free2023-05-14Windows Process Command Line Matching Goofy-Guineapig Backdoor Command Fragment
Alerts on Windows process command lines containing a specific non-interactive choice command often used in automation.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2023-05-14Windows File Indicators for Goofy Guineapig Malware IOCS
Flags Windows file events involving specific Goofy Guineapig backdoor indicator filenames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh71Free2023-05-14Windows Certificate Export from Local Certificate Store (Event ID 1007)
Flags Windows events where a certificate is exported from the local certificate store via Certificate Services client telemetry.
Zach Mathis, Huntrule TeamWindowscertificateservicesclient-lifecycle-systemMedium123Free2023-05-13Windows CAPI2 Event 70: Certificate Private Key Acquired
Detects when Windows CAPI2 logs that a process acquired a certificate private key (EventID 70).
Zach Mathis, Huntrule TeamWindowscapi2Medium151Free2023-05-13Windows Excel Loads .XLL Add-in from Uncommon File Paths
Flags Excel loading .xll add-ins from uncommon directories based on image load paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium93Free2023-05-12Windows Excel Loads .XLL Add-In Files
Flags excel.exe loading a .XLL add-in module, an execution indicator for potential malicious add-in activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadLow110Free2023-05-12