Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,429 rules
Windows Registry Persistence: Uncommon .wav OpenWithProgIds Value Creation
Flags registry value writes under .wav OpenWithProgIds with unusual naming that may indicate persistence behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium137Free2023-05-10Windows File Creation: Non-System WerFault.exe Created in WinSxS
Flags creation of C:\Windows\WinSxS\WerFault.exe by processes outside core Windows system directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh151Free2023-05-10Windows file events matching SNAKE-related installer filename indicators
Flags Windows file events with target filenames ending in common SNAKE installer indicators like jpsetup.exe and jpinst.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow132Free2023-05-10Windows File Indicator: SNAKE Malware Kernel Driver Target File Comadmin.dat
Alerts on Windows file events involving C:\Windows\System32\Com\Comadmin.dat, an indicator tied to SNAKE kernel driver activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical243Free2023-05-10PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh235Free2023-05-09Windows: New PowerShell Module Files Created by Non-PowerShell Processes
Detects new PowerShell module files written into Modules directories by processes other than expected PowerShell hosts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium141Free2023-05-09Windows PowerShell Module File Creation via PowerShell Processes
Alert when PowerShell creates module-related files under WindowsPowerShell or PowerShell 7 module directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow152Free2023-05-09Windows PowerShell dropping a .ps1 script from powershell.exe or pwsh.exe
Alerts when PowerShell creates a dropped .ps1 script file on Windows, excluding common benign temp and test outputs.
frack113, Huntrule TeamWindowsfile_eventLow374Free2023-05-09Windows PowerShell Import-Module Cmdlet Execution
Flags PowerShell command lines containing Import-Module, indicating module loading into the current session.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-05-09System Informer Execution on Windows Process Creation
Alerts on Windows executions of SystemInformer.exe using matching filenames, metadata, and known hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2023-05-08Windows File Event: Flag Cyrillic Homoglyph Characters in Target Filename
Alerts on Windows file events with TargetFilename containing ASCII lookalike Unicode characters.
Micah Babinski, @micahbabinski, Huntrule TeamWindowsfile_eventMedium283Free2023-05-08Windows PUA System Informer Driver Load via SystemInformer.sys
Alerts on loading SystemInformer.sys as a Windows driver when matched against known System Informer SHA256 hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadMedium81Free2023-05-08Windows Process Command Line Matches Perfect Homoglyph Unicode Characters
Alerts when a Windows process command line includes Unicode homoglyphs that look like ASCII letters.
Micah Babinski, @micahbabinski, Huntrule TeamWindowsprocess_creationMedium162Free2023-05-07Windows ImageLoad of SolidPDFCreator.dll from Unexpected Paths
Alerts when SolidPDFCreator.dll is loaded from a non-standard process or path, consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium71Free2023-05-07Okta FastPass blocks phishing authentication attempts via MFA
Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.
Austin Songer @austinsonger, Huntrule TeamOktaoktaHigh254Free2023-05-07