Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.
Nounou Mbeiri, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh258Free2024-06-26Detects Unauthenticated Command Injection Attempts Against TP-Link Archer AX21 via Proxy Requests
Alerts on proxy HTTP GET/POST requests targeting Archer AX21 CGI locale/country write parameters consistent with command injection attempts.
Nasreddine Bencherchali (Nextron Systems), Rohit Jain, Huntrule Team—proxyMedium3710Free2024-06-25Windows Process Execution: LaZagne Credential Dumping Utility (lazagne.exe)
Flags Windows process launches consistent with running LaZagne (lazagne.exe) for credential and password recovery.
Nasreddine Bencherchali, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2024-06-24Windows Network Connections to azurewebsites.net from Non-Browser Processes
Alerts on outbound connections to azurewebsites.net started by non-browser processes on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium162Free2024-06-24Windows File Creation: System DLL Named .dll in Uncommon Locations
Alerts on creation of .dll files named like system DLLs in unexpected Windows directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium123Free2024-06-24Windows DNS Queries to azurewebsites.net From Non-Browser Processes
Alerts on DNS queries to azurewebsites.net from processes other than common browsers, using Windows DNS query and process image telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns_queryMedium207Free2024-06-24Windows CSharp Streamer RAT Potentially Loaded .NET Executable from Temp dat####.tmp
Identifies .NET executable image loads from a CSharp Streamer RAT-like Temp .tmp path pattern on Windows.
Luca Di Bartolomeo, Huntrule TeamWindowsimage_loadHigh372Free2024-06-22Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Alerts on initiated outbound connections from Windows hosts to LocaltoNet/.localtonet.com tunneling domains.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsnetwork_connectionHigh163Free2024-06-17Linux: Network connections initiated to LocaltoNet tunneling subdomains
Alerts when a Linux host initiates outbound connections to LocaltoNet (.localto.net/.localtonet.com) tunneling subdomains.
Andreas Braathen (mnemonic.io), Huntrule TeamLinuxnetwork_connectionHigh4510Free2024-06-17macOS Process Creation: nscurl File Download Arguments
Flags nscurl executions on macOS that include download-oriented command-line options, indicating potential remote file retrieval.
Daniel Cortez, Huntrule TeamMacosprocess_creationMedium93Free2024-06-04Windows: Suspicious Qemu execution with low-memory and network-tunneling flags
Alerts on Windows Qemu command lines using low -m values plus -netdev/connect= and -nographic.
Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR), Huntrule TeamWindowsprocess_creationMedium182Free2024-06-03Windows Recall Enabled by Registry: DisableAIDataAnalysis Set to 0 (Windows)
Alerts when Windows Recall is enabled by setting the DisableAIDataAnalysis policy value to 0.
Sajid Nawaz Khan, Huntrule TeamWindowsregistry_setMedium131Free2024-06-02Windows Recall Enabled by Deleting DisableAIDataAnalysis Registry Value
Flags deletion of WindowsAI\DisableAIDataAnalysis policy value indicating Windows Recall may be enabled.
Sajid Nawaz Khan, Huntrule TeamWindowsregistry_deleteMedium3910Free2024-06-02Windows Recall Enabled via reg.exe Registry Changes (Windows)
Flags reg.exe commands that delete or set DisableAIDataAnalysis to 0 under WindowsAI to enable Windows Recall.
Sajid Nawaz Khan, Huntrule TeamWindowsprocess_creationMedium162Free2024-06-02Windows Executable Connects to portmap.io Domain Over Network
Alerts when a Windows process initiates a connection to a .portmap.io destination hostname.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium102Free2024-05-31