Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,284 rules
Windows vmnat.exe Renamed Execution for Possible DLL Side-Loading
Alerts on Windows processes where vmnat.exe appears renamed, which may support stealthy execution and DLL side-loading behavior.
elhoim, Huntrule TeamWindowsprocess_creationHigh103Free2022-09-09PowerShell User Discovery and Export with Get-ADUser
Flags PowerShell Get-ADUser enumeration (filter *) followed by exporting results to a file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium481Free2022-09-09Windows Root Certificate Installation from Suspicious Paths via PowerShell Import-Certificate
Alerts on PowerShell importing a root certificate into Cert:\LocalMachine\Root from suspicious file paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-09-09PowerShell Email Address Exfiltration via EXIF-style Recipient Harvesting on Windows
Alerts when PowerShell command lines enumerate Exchange recipients and expand email address properties, indicating potential email data exfiltration.
Nasreddine Bencherchali (Nextron Systems), Azure-Sentinel (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-09Windows node.exe Execution with -e/--eval and suspicious child process usage
Alerts on node.exe started with -e/--eval and command-line indicators of child_process and net.socket connect activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh182Free2022-09-09Windows Security: Suspicious SAMTHEADMIN-* Computer/Account Names Ending with $
Alerts on Windows Security events with computer account names starting SAMTHEADMIN- and ending with $.
elhoim, Huntrule TeamWindowssecurityCritical171Free2022-09-09Windows WMIC System Reconnaissance Using "computersystem" Flag
Flags wmic.exe runs that include the "computersystem" argument for Windows host information discovery.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium92Free2022-09-08Windows Process Creation: SharpEvtMute Execution (Event Log Tampering)
Alerts on SharpEvtMute.exe runs with event-log filter and encoded command-line parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2022-09-07Windows SysmonEnte Process Access Attempt (Sysmon.exe/ Sysmon64.exe/ Sysmon64a.exe)
Flags attempts to access Sysmon binaries consistent with SysmonEnte execution based on TargetImage, GrantedAccess, and CallTrace.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh435Free2022-09-07Windows: Detect EvtMuteHook.dll Load by IMPHASH Match (SharpEvtMute)
Detects DLL loads with a specific IMPHASH consistent with EvtMuteHook.dll used for event log tampering.
Florian Roth (Nextron Systems), Huntrule TeamWindowsimage_loadHigh92Free2022-09-07Windows suspicious file download URLs using direct IP address with script/binary extensions
Alerts on Windows downloads from HTTP/HTTPS direct IP URLs targeting script/binary/shortcut-like filenames.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh113Free2022-09-07Windows Process Creation: WinAPI Function Names in Command-Line
Alerts on Windows processes whose command lines reference WinAPI functions/modules commonly used for dynamic invocation and memory/process manipulation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-06Windows Process Creation: Renamed Sysinternals Sdelete Execution
Alerts on Windows processes created with OriginalFileName sdelete.exe but executed via renamed sdelete binary paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-09-06Windows PowerShell DNS TXT Download Cradle via nslookup (Process Creation)
Flags PowerShell spawning nslookup configured to query DNS TXT records as a download cradle.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2022-09-05Windows SharpChisel Command-Line Execution via SharpChisel.exe
Alerts on Windows process executions where the SharpChisel executable or Product metadata indicates SharpChisel.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2022-09-05