Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,421 rules
Windows Registry: Hypervisor Enforced Code Integrity Enabled DWORD Set to 0
Alerts when HVCI-related registry values are set to 0, indicating Hypervisor Enforced Code Integrity has been disabled.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsregistry_setHigh141Free2023-03-14Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh199Free2023-03-14Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Flags Sysinternals ADExplorer running with "snapshot" to create a local Active Directory database copy.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-03-14Windows AD Structure Export Using ldifde.exe with -f
Flags ldifde.exe executions using -f that indicate Active Directory structure export from a Windows host.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-03-14Windows Process Creation: dotnet-dump.exe collect Flag
Flags dotnet-dump.exe executions using the collect parameter, which may indicate memory dumping of sensitive processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium172Free2023-03-14Windows: Detect csvde.exe Active Directory export to CSV
Flags csvde.exe executions on Windows that include -f, consistent with exporting Active Directory data for discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium237Free2023-03-14Windows Registry Event for Potential Qakbot/IceID Persistence Key
Alerts on Windows registry events referencing a specific \\Software\\firm\\soft\\Name key suffix linked to Qakbot/IceID-like activity.
Hieu Tran, Huntrule TeamWindowsregistry_eventHigh132Free2023-03-13Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
Hieu Tran, Huntrule TeamWindowsprocess_creationHigh91Free2023-03-13Windows PowerShell Downloading DLLs via Invoke-WebRequest or Invoke-RestMethod
Alerts on PowerShell using web request cmdlets to download an HTTP DLL to disk.
Florian Roth (Nextron Systems), Hieu Tran, Huntrule TeamWindowsprocess_creationMedium70Free2023-03-13PowerShell GzipStream Decompression Attempts on Windows
Detects Windows PowerShell commands using GZipStream and ::Decompress to decompress encoded Gzip data.
Hieu Tran, Huntrule TeamWindowsprocess_creationMedium123Free2023-03-13Windows Wazuh Platform DLL Side-Loading via ImageLoad of libwazuhshared.dll
Alerts on suspicious loading of Wazuh platform DLLs in Windows image load telemetry, excluding common Program Files and Mingw64 patterns.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium151Free2023-03-13Windows Rcdll.dll DLL Sideloading via Image Load Path
Flags rcdll.dll loads from unexpected locations, excluding Visual Studio and Windows Kits directories.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh133Free2023-03-13Windows AMSI.DLL Image Load by Uncommon Process Paths
Alerts when Amsi.dll is loaded by processes outside common Windows binaries and directories.
frack113, Huntrule TeamWindowsimage_loadLow120Free2023-03-12Windows 7-Zip Extracts Password-Protected Archives via 7z/7za/7zr
Flags 7-Zip (7z/7za/7zr) command lines that include -p with x extraction and -o output, indicating password-protected archive extraction.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow90Free2023-03-10Windows Process Creation: mshta/VBScript Launching PowerShell and Embedded Backdoor Logic
Alerts on Windows command lines combining mshta VBScript execution bypass, system survey WMI queries, and PowerShell HTTP/Base64 patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2023-03-10