Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry: New AppCompatFlags custom shim databases targeting system processes
Alerts on Windows registry writes to AppCompatFlags Custom shim paths targeting common system processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh303Free2023-08-01Windows sdbinst.exe Installing Shim Database with Uncommon Extension
Flags sdbinst.exe process executions consistent with installing shim databases using uncommon .sdb command-line patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium464Free2023-08-01Windows VMMap Loading Unsigned dbghelp.dll from C:\Debuggers\dbghelp.dll
Alerts when VMMap loads an unsigned dbghelp.dll from C:\Debuggers, suggesting DLL sideloading on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh112Free2023-07-28Windows CreateRemoteThread in mstsc.exe From Suspicious Source Paths
Alerts when mstsc.exe creates remote threads from processes running out of common suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_remote_threadHigh249Free2023-07-28FortiGate Web Exploitation Indicators for CVE-2023-27997 via Remote Host/Login Checks
Flags GET/POST requests to FortiGate /remote validation/login endpoints containing "enc=" as potential CVE-2023-27997 exploitation indicators.
Sergio Palacios Dominguez, Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverMedium371Free2023-07-28Windows: Alert on wget.exe downloading files from an IP with output flags
Flags Windows wget.exe usage to download HTTP URLs from IPs and write outputs to script/binary extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3510Free2023-07-27Windows: curl.exe Local File Read via file:/// Command Line
Flags curl.exe runs that include file:/// to access local files on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-07-27Windows: Curl.exe Insecure Proxy/DOH Transfer Flags
Flags curl.exe with --proxy-insecure and/or --doh-insecure during Windows process execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium70Free2023-07-27Suspicious curl.exe File Downloads From Direct IP Addresses on Windows
Alerts on Windows curl.exe commands downloading from an IP address with HTTP/S and suspect file extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2023-07-27Windows Process Execution: curl.exe with Custom User-Agent Header
Flags Windows executions of curl.exe that include a User-Agent header in the command line.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2023-07-27Windows Process Execution: curl.exe Saving Cookies via -c / --cookie-jar
Flags curl.exe commands that save cookie jar data using -c/--cookie-jar on Windows process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium331Free2023-07-27Windows Terminal settings.json modified by uncommon process
Alerts on Windows Terminal settings.json changes made by an uncommon command-line or script host process.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium72Free2023-07-22Windows net.exe Uses QUIC Transport to Mount SMB Shares
Alerts on net.exe commands mounting SMB shares over QUIC transport (/TRANSPORT:QUIC), using process creation logs.
frack113, Huntrule TeamWindowsprocess_creationMedium60Free2023-07-21Windows PowerShell ScriptBlock WinAPI Function Calls
Find PowerShell script blocks that reference WinAPI/native-call function names tied to process, memory, token, or thread operations.
Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium70Free2023-07-21PowerShell Scripts Calling WinAPI DLLs on Windows
Detects PowerShell script blocks that reference WinAPI-related Windows DLLs such as kernel32.dll and ntdll.dll.
Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium70Free2023-07-21