Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows: Detect regedit.exe creating a PDF file
Alerts when RegEdit.exe creates a .pdf file on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh256Free2024-07-08Windows Registry: DisableHypervisorEnforcedPagingTranslation Set to 1
Alerts when Windows disables Hypervisor Enforced Paging Translation by setting DisableHypervisorEnforcedPagingTranslation to 1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh103Free2024-07-05Windows Security Event 4698: Kapeka-like Scheduled Task Creation
Flags suspicious Kapeka-like scheduled task creation via Event 4698 using TaskContent paths, rundll32/.wll command markers, and OneDrive/Sens Api task names.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowssecurityHigh298Free2024-07-03Windows Registry Seed Value Set Under Cryptography\Providers (Kapeka SIP Persistence)
Flags registry set operations creating/setting a "Seed" value under the Cryptography Providers key path on Windows.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setMedium142Free2024-07-03Windows Registry Run Key Autorun Entries Targeting Kapeka Backdoor
Flags Windows Run key registry changes whose data matches a Kapeka-style rundll32 .wll (#1) autorun entry.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsregistry_setHigh111Free2024-07-03Kapeka backdoor execution via rundll32.exe with export ordinal #1 and -d on Windows
Flags rundll32.exe command lines launching a Kapeka payload from ProgramData/AppData Local using export ordinal #1 with "-d".
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh239Free2024-07-03Windows Kapeka Backdoor Persistence via schtasks ONSTART or Run Registry Autorun
Flags Windows persistence creation for Kapeka using schtasks (ONSTART) or Run registry entries plus rundll32 ordinal-based execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh504Free2024-07-03Windows: Kapeka backdoor DLL (.wll) loaded via rundll32.exe
Flags rundll32.exe loading a suspicious .wll backdoor from ProgramData or AppData\Local.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh223Free2024-07-03Windows file drop: Kapeka-style decrypted backdoor indicators in AppData with .wll naming
Alerts on suspicious Kapeka backdoor file drops in Windows AppData/Common AppData using .wll naming patterns.
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh466Free2024-07-03Windows Registry: EnablePeriodicBackup value set for periodic system hive backups
Alerts on enabling the Windows registry setting that triggers periodic system hive backups to RegBack on restarts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium122Free2024-07-01Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Flags and image indicators for RemoteKrbRelay execution on Windows, including relaying-related command-line actions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh387Free2024-06-27Windows File Drop Indicators for RemoteKrbRelay SMB Relay Secret Dump Module
Alerts on creation of RemoteKrbRelay-specific temp files used to stage secrets dump outputs on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh324Free2024-06-27Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule TeamWindowsprocess_creationHigh211Free2024-06-26SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2024-06-26Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh161Free2024-06-26