Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Creation From Fake Recycle.Bin Directories
Alerts on Windows processes launched from fake RECYCLER.BIN / RECYCLERS.BIN folder paths often used for stealth.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh329Free2023-07-12Windows: wordpad.exe Initiated Network Connections on Uncommon Ports
Alerts when wordpad.exe initiates outbound connections on destination ports outside common C2-related ports.
X__Junior (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium141Free2023-07-12Windows Office Apps Initiating Network Connections to Non-Common Ports
Alerts on network connections initiated by Windows Office apps to destination ports not in the common port set.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium427Free2023-07-12Windows: Suspicious File Creation in Fake RECYCLER.BIN Staging Folders
Alerts on Windows file writes involving RECYCLERS.BIN\ or RECYCLER.BIN\ paths often used for staging.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh408Free2023-07-12HTTP GET Requests Containing /MSHTML_C7/ URL Marker (Proxy Logs)
Alerts on proxy HTTP GET requests whose URI contains /MSHTML_C7/.
X__Junior, Huntrule Team—proxyHigh123Free2023-07-12Proxy GET Requests for Suspicious File and Redirect Paths Associated with CVE-2023-36884
Alerts on proxy HTTP GET requests for specific suspicious file-download URI patterns associated with CVE-2023-36884-style activity.
X__Junior, Huntrule Team—proxyMedium297Free2023-07-12Proxy GET Requests with IP-Embedded CVE-Related URL Parameters
Finds proxy GET URIs with risky extensions and a d=IPv4 parameter value in the query string.
X__Junior, Huntrule Team—proxyHigh431Free2023-07-12Proxy HTTP GET Pattern Matching /MSHTML_C7/ with IPv4 Query Parameters
Alerts on proxy HTTP GET requests to /MSHTML_C7/ with an IPv4-like query parameter pattern.
X__Junior, Huntrule Team—proxyCritical120Free2023-07-12Windows DLL Sideloading via Abusable DLLs Loaded from Suspicious Locations
Flags Windows module loads of specific abusable DLL names from public, temp, or user folders consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh445Free2023-07-11Windows PowerShell Script Accessing Windows MailApp MailBox Data Path
Identifies PowerShell scripts referencing the Windows MailApp mailbox data path, which may indicate email data access or manipulation.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2023-07-08Windows: Recon command output piped to findstr.exe
Alerts on Windows command lines running recon commands whose output is filtered with findstr.exe.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium81Free2023-07-06PowerShell Registry Reconnaissance Indicators on Windows via Script Block Logging
Identifies PowerShell script blocks querying sensitive registry keys tied to services and Run/Explorer/winlogon locations.
frack113, Huntrule TeamWindowsps_scriptMedium70Free2023-07-02Windows process creation: WerFault.exe executed with -pr flag
Alerts when WerFault.exe is launched with the -pr argument, potentially indicating ReflectDebugger-based execution.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-06-30Windows PowerShell Decryption-Like Activity Involving .LNK File Processing
Identifies PowerShell runs that enumerate and process *.lnk content using byte-level reads/writes consistent with decryption staging.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2023-06-30Windows Process Execution of curl.exe with --insecure Flag
Flags curl.exe launched with --insecure/-k to disable TLS certificate verification.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium102Free2023-06-30