Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows sc.exe Service Query for termservice Enumeration
Alerts on sc.exe service querying that references termservice on Windows.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationLow321Free2024-02-12Windows: AnyDesk Execution Using Revoked Certificate Versions
Detects AnyDesk.exe execution on Windows when the file version matches known revoked-certificate releases (excluding uninstall/remove).
Sai Prashanth Pulisetti, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium413Free2024-02-08FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching
Flags FortiOS sslvpnd activity containing known CVE-2022-42475 artifact paths from file-related events.
Nasreddine Bencherchali (Nextron Systems), Nilaa Maharjan, Douglasrose75, Huntrule TeamFortiossslvpndHigh255Free2024-02-08Windows iexpress.exe Creates Self-Extracting Binaries Using SED Files From Suspicious Paths
Flags suspicious use of Windows iexpress.exe to create self-extracting packages via SED directives from uncommon/temp paths.
Joseliyo Sanchez, @Joseliyo_Jstnk, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh235Free2024-02-05Windows: Alerts on Creation of .sed Self-Extraction Directive File
Flags creation of newly created .sed directive files on Windows, which can be used for self-extracting package abuse.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_executable_detectedMedium241Free2024-02-05Windows Self Extraction Directive (.sed) File Created in Suspicious Paths
Alerts on .sed directive file creation under ProgramData/Temp/Tasks paths on Windows, consistent with iExpress-based packaging abuse.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsfile_eventMedium123Free2024-02-05Windows Process Creation: IExpress.exe Creating Self-Extracting Packages
Identifies IExpress.exe usage to generate self-extracting packages, including makecab.exe involvement and IExpress command-line patterns.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium90Free2024-02-05Windows WMI Disk and Volume Discovery via WMIC.exe
Flags WMIC.exe process executions that query Win32 logical disk and volume listing details.
Stephen Lincoln '@slincoln-aiq' (AttackIQ), Huntrule TeamWindowsprocess_creationMedium454Free2024-02-02Windows SharpMove (.NET) Execution via SharpMove.exe and Action Command-Line Flags
Alerts on SharpMove.exe process execution with command-line actions for DCOM, WMI VBS, and task scheduler.
Luca Di Bartolomeo (CrimpSec), Huntrule TeamWindowsprocess_creationHigh71Free2024-01-29Windows EDRSilencer Execution via Filtering Platform FilterName Change
Detects Filtering Platform custom outbound filter additions associated with potential EDRSilencer execution on Windows.
Thodoris Polyzos (@SmoothDeploy), Huntrule TeamWindowssecurityHigh398Free2024-01-29Windows Process Creation: SOAPHound Execution via AD Data Collection Command-Line Arguments
Flags SOAPHound execution on Windows by detecting command-line arguments used for Active Directory data collection.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh349Free2024-01-26Uncommon ADWS (Port 9389) Connections from Non-Standard Windows Binaries
Alerts on unexpected process-to-ADWS (TCP/9389) connections on Windows to highlight potential directory discovery.
"@kostastsale, Huntrule Team"Windowsnetwork_connectionMedium81Free2024-01-26Windows: Suspicious rundll32 Execution of Non-DLL Extension via Living-off-the-Land Parent Processes
Flags rundll32.exe executions from common script parents where the command line references known drop locations but lacks standard extensions.
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2024-01-26Windows: Detect MODE.COM Changing Code Page Settings
Detects MODE.COM executions that include code page selection parameters.
Nasreddine Bencherchali (Nextron Systems), Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationLow60Free2024-01-19Windows Code Page Change via mode.com Selecting Russian Code Pages
Alerts when mode.com is used to set console code pages to Russian values (1251 or 866).
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium212Free2024-01-17