Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,344 rules
Windows Named Pipe Creation: PAExec Default Pipe (\PAExec*)
Alerts on named pipe creations starting with "\PAExec" associated with PAExec default behavior on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdMedium4610Free2022-10-26Windows Exchange PowerShell Cmdlet History Log Files Deleted
Flags deletion of Exchange PowerShell cmdlet history log files in the expected logging directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteHigh161Free2022-10-26Windows Service Control Manager: Detect PAExec- service installation
Flags creation of PAExec-named Windows services with image paths under C:\WINDOWS via Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium269Free2022-10-26Windows: Registry change disabling MacroRuntimeScanScope runtime macro scanning
Flags Office registry updates that set MacroRuntimeScanScope to 0x00000000, disabling runtime scanning for enabled macros.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh1610Free2022-10-25Windows CLI Searching for JWT Strings (eyJ0eX / eyJhbGci) in Command Line
Flags Windows CLI token hunting when search utilities are used alongside JWT-like substrings in the command line.
Nasreddine Bencherchali (Nextron Systems), kagebunsher, Huntrule TeamWindowsprocess_creationMedium112Free2022-10-25Windows Image Load: Suspicious DLL Sideloading of dbghelp.dll
Alerts on dbghelp.dll being loaded from non-standard locations, indicating possible DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium101Free2022-10-25Windows Image Load Alerts for dbgcore.dll Sideloading
Alerts when dbgcore.dll is loaded from paths outside typical Windows directories, indicating possible DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium132Free2022-10-25OpenSSH Server (sshd) Listening on SSH Socket on Windows
Flags OpenSSH (sshd) events showing the SSH server has started listening on a socket.
mdecrevoisier, Huntrule TeamWindowsopensshMedium143Free2022-10-25Inveigh Execution via Process Creation (Windows)
Detects execution of Inveigh.exe on Windows with spoofing/sniffing command-line flags consistent with MITM behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical305Free2022-10-24PowerShell: Suspicious Set-Service DACL/SecurityDescriptor Modification for Hidden Services
Flags PowerShell ScriptBlock activity using Set-Service with specific SDDL elements consistent with hiding services from tools like sc.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh82Free2022-10-24Windows Inveigh HackTool Execution Artefacts via Inveigh File Indicators
Alert on Windows file creation or presence of Inveigh log, script, and binary artefacts identified by distinctive filename suffixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical427Free2022-10-24Windows MsiInstaller installs remote MSI from web URLs (EventID 1040/1042)
Flags Windows Installer MsiInstaller events that indicate downloading and installing an MSI from a URL.
Stamatis Chatzimangou, Huntrule TeamWindowsapplicationMedium112Free2022-10-23Windows Alternate Data Stream Creation: Suspicious Zone.Identifier ADS Outside Browser Download
Flags suspicious creation of :Zone.Identifier ADS streams (ZoneTransfer/ZoneId=3) on file types outside typical browsers.
frack113, Huntrule TeamWindowscreate_stream_hashMedium121Free2022-10-22Windows: Suspicious Child Processes Spawned by Electron Apps
Flags suspicious command/scripting child processes launched by Electron apps such as Teams, Discord, Slack, and Edge.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium347Free2022-10-21Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Alerts when onenote.exe spawns suspicious script or system execution child processes on Windows, consistent with malicious OneNote payload behavior.
Tim Rauch (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Elastic (idea), Huntrule TeamWindowsprocess_creationHigh60Free2022-10-21