Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,281 rules
Windows SharpLdapWhoami Execution via LDAP Whoami Methods
Flags execution of SharpLdapWhoami on Windows using LDAP-related whoami alternative method parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh178Free2022-08-29Potential DLL Sideloading via DeviceEnroller.exe Using /PhoneDeepLink
Alerts on deviceenroller.exe runs with /PhoneDeepLink, a potential DLL sideloading trigger referencing ShellChromeAPI.dll.
"@gott_cyber, Huntrule Team"Windowsprocess_creationMedium449Free2022-08-29Windows Registry Detection: COM TreatAs(Default) Hijacking
Flags registry changes to COM TreatAs(Default) keys, excluding common Office/ClickToRun and installer processes.
frack113, Huntrule TeamWindowsregistry_setMedium92Free2022-08-28Windows Process Creation: nimgrab.exe Execution (Nim Tool Download Behavior)
Alerts on execution of nimgrab.exe on Windows when hashes match known indicators.
frack113, Huntrule TeamWindowsprocess_creationHigh163Free2022-08-28Windows Network Connections by wscript/cscript Script Interpreters to Non-Local IPs
Flags wscript.exe/cscript.exe making outbound connections to non-local destination IPs.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh141Free2022-08-28Windows Wscript/Cscript Initiating Local Network Connection for Script Retrieval
Flags wscript.exe or cscript.exe making connections to local/private destination IP ranges on Windows.
frack113, Huntrule TeamWindowsnetwork_connectionMedium93Free2022-08-28Windows Scheduled Task Index Registry Tampering Hiding Tasks from Query Tools
Alerts on registry set events that tamper scheduled task TaskCache Tree "Index" DWORD to 0.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh123Free2022-08-26Windows Registry: Scheduled Task Index Value Removal to Hide Task (TaskCache)
Alerts on deletion of the Scheduled Tasks TaskCache Tree 'Index' value used by tools to enumerate tasks.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_deleteMedium151Free2022-08-26Suspicious SysAidServer Child Processes via Java on Windows
Flags SysAidServer process spawning java.exe/javaw.exe on Windows to surface likely suspicious execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2022-08-26Windows Process Execution: Suspicious PowerShell Encoded Command with Exec Bypass
Flags Windows process creations with a bypass-and-encoded PowerShell Start-Job command-line pattern linked to Mercury-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh324Free2022-08-26Windows Process Execution of Regasm/Regsvcs from Uncommon Directories
Alerts on Regasm/Regsvcs executions from commonly abused non-standard directories using process creation image and command line fields.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2022-08-25Windows process command line matching Sliver C2 implant NoExit PowerShell UTF8 pattern
Alerts on Windows process command lines matching a Sliver-style PowerShell -NoExit encoding pattern.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical152Free2022-08-25Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh264Free2022-08-25Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2022-08-24Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Flags Sysinternals-related registry EULA acceptance writes tied to PsExec/ProcDump/Process Explorer and other tools.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium70Free2022-08-24