Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
49 rules
Windows AppX Packaging: Execute AppX with Suspicious Digital Signature Certificate
Alerts when AppX package execution/signature subject matches a known suspicious certificate in Windows telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxpackaging-omMedium112Free2023-01-16Windows AppX Deployment: Uncommon Appx Path Added to Deployment Pipeline
Alerts when an AppX package is queued for processing from uncommon paths or URLs in Windows AppX deployment server events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium101Free2023-01-11Windows AppX Deployment Blocked by Local Policy
Detects blocked AppX package deployments on Windows via AppXDeployment-Server policy-denial Event IDs.
frack113, Huntrule TeamWindowsappxdeployment-serverMedium153Free2023-01-11Windows AppX Package Deployment: Suspicious AppX Installation Attempts by PackageFullName
Alerts on Windows AppX deployment events tied to a known-malicious AppX package identifier.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverMedium162Free2023-01-11Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh101Free2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsappxdeployment-serverHigh426Free2023-01-11Windows AppX deployment blocked by AppLocker (AppXDeployment-Server EventID 412)
Flags AppX package deployment attempts that AppLocker blocked, based on AppXDeployment-Server EventID 412.
frack113, Huntrule TeamWindowsappxdeployment-serverMedium273Free2023-01-11Linux Package Installation via apt/yum/rpm/dpkg with Networking Tools Keywords
Alerts when apt/yum/rpm/dpkg install commands include reconnaissance or proxy tool keywords.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium488Free2023-01-03Windows Registry: Appx DebugPath Key for Potential Persistence
Detects registry set activity involving AppX DebugPath entries that may indicate persistence via packaged app debug configuration.
frack113, Huntrule TeamWindowsregistry_setMedium398Free2022-07-27Windows File Creation of .diagcab Packages
Alerts on newly created Windows .diagcab files that may indicate malicious packaging or exploitation.
frack113, Huntrule TeamWindowsfile_eventMedium176Free2022-06-08Linux chmod Process Commandlines Targeting Sensitive Directory Paths
Flags Linux chmod commands that modify permissions for paths under /tmp/, /.Library/, /etc/, or /opt/, excluding several known benign package-maintenance patterns.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamLinuxprocess_creationMedium183Free2022-06-03Windows msiexec.exe Initiates Outbound HTTP(S) Connection on Port 80/443
Alerts when msiexec.exe starts outbound connections to ports 80 or 443, indicating potential remote package retrieval.
frack113, Huntrule TeamWindowsnetwork_connectionLow90Free2022-01-16Windows DNS Queries Triggered by DesktopAppInstaller AppInstaller.EXE
Identifies DNS lookups performed by Windows AppInstaller.EXE when initiating ms-appinstaller package installation from a URL.
frack113, Huntrule TeamWindowsdns_queryMedium335Free2021-11-24Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh363Free2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventHigh162Free2020-10-29