Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,429 rules
Windows Wget.exe Downloads From File-Sharing Domains Matching Suspicious Output Flags
Flags wget.exe executions on Windows that download via HTTP from known file-sharing domains and write specific file extensions to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh425Free2023-05-05Windows curl.exe Downloads from File-Sharing Domains with Suspicious Output Extensions
Alerts on curl.exe downloading files over HTTP from file-sharing/content hosting domains, based on process command-line and executable context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-05-05PowerShell Script Reading Files and Resolving DNS Host Entries
Identifies PowerShell scripts that read files, resolve DNS host entries, and output results to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium1810Free2023-05-05Windows DLL Sideloading: libcurl.dll Loaded by gup.exe from Uncommon Location
Alerts when gup.exe loads libcurl.dll from a path that doesn’t match the excluded Notepad++ GUP.exe location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium415Free2023-05-05Windows: File creation of a Procmon-named .sys driver by non-procmon processes
Alerts when a procmon-named .sys driver is created by a process other than procmon.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium132Free2023-05-05Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh465Free2023-05-05Windows Suspicious File Creation in C:\PerfLogs with Executable/Script Extensions
Alerts on creation of potentially malicious file types in C:\PerfLogs\ on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium151Free2023-05-05Windows: File Creation of NTDS.DIT (Active Directory Database)
Flags creation of an ntds.dit file on Windows, an Active Directory database artifact often associated with credential access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow172Free2023-05-05Windows Process: sqlcmd.exe Querying Veeam Backup Databases
Flags sqlcmd.exe command lines querying Veeam backup database objects associated with repository and credential data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium4310Free2023-05-04Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical415Free2023-05-04Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh122Free2023-05-04Proxy User-Agent starts with Base64-like prefixes associated with encoded client strings
Identifies proxy requests with User-Agent values starting with known Base64-encoded prefixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebproxyMedium234Free2023-05-04Windows PowerShell Script Block Matching POWERTRASH Behavior Indicators
Detects PowerShell ScriptBlock text containing POWERTRASH-related in-memory and dynamic execution indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2023-05-04PowerShell ScriptBlock Launching wscript.exe via PowerHold-like Code Patterns on Windows
Flags PowerShell ScriptBlock text that writes staged bytes in APPDATA and launches wscript.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh161Free2023-05-04Windows PowerShell Script File Creation Matching FIN7-Style Filenames
Alerts on Windows PowerShell script drops named host_ip.ps1 or ending with _64refl.ps1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh112Free2023-05-04