Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry: Uncommon Microsoft Office Trusted Location Path Added
Alerts on registry changes adding non-standard Microsoft Office Trusted Location paths that could undermine macro security.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh163Free2023-06-21Windows Registry TrustRecords Change for Macro-Enabled Documents in Suspicious Paths
Alert on Windows registry changes to Office TrustRecords where trusted-document paths fall in suspicious directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh131Free2023-06-21Windows: Office Executable Running a Document from Trusted Template/Startup Paths
Alerts when Office apps are launched with command lines pointing to documents under Office template/Startup paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2023-06-21Windows Registry: Microsoft Office Trusted Location Keys Updated
Alerts on Office “Trusted Locations” registry changes, excluding typical Click-to-Run and Office install activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium50Free2023-06-21Windows rundll32.exe Using ShellExecute via ShellDispatch.dll Functionality
Alerts on rundll32.exe command lines referencing RunDll_ShellExecuteW, suggesting ShellDispatch.dll ShellExecute-based execution.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2023-06-20Windows ShellDispatch.dll DLL Sideloading via Image Load Monitoring
Alerts on suspicious loads of ShellDispatch.dll on Windows when not occurring in expected temp directories.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium152Free2023-06-20Windows DLL side-loading via appverifUI.dll image loads
Alerts when appverifUI.dll is loaded on Windows from unexpected paths, a common DLL sideloading technique.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh214Free2023-06-20Windows Security 4719: Important Audit Policy Categories Disabled
Alerts on Windows Security 4719 indicating auditing was disabled for important security event subcategories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityHigh186Free2023-06-20Linux Named Pipe Creation via mkfifo in /tmp
Flags mkfifo executions that create named pipes in /tmp, a commonly abused location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium100Free2023-06-16Linux Named Pipe Creation via mkfifo Process Execution
Flags Linux process executions of /mkfifo that create named pipes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow90Free2023-06-16Linux Process Execution of BarracudaMailService and Resize Utility Binaries
Alerts on Linux process creation for executables ending with three specific names linked to SEASPY deployment.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationCritical141Free2023-06-16Linux Process Creation: wget Download Tar From Untrusted Direct IP with No-Check-Certificate
Flags wget commands that download .tar files from direct IP URLs while bypassing TLS certificate validation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh225Free2023-06-16Linux Process: Wget Downloads .zip/.rar from temp.sh URL
Identifies Linux wget commands that download .zip or .rar archives from temp.sh.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh152Free2023-06-16Linux openssl s_client Connections to External IPs for SSL Certificate Exfiltration
Detects openssl s_client connecting to an IP:port on 443/8080 from Linux process command lines.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh113Free2023-06-16Linux File Indicators Matching Suspected Barracuda ESG Exploitation Artifacts
Flags Linux file creation/access events whose filenames end with known Barracuda ESG exploitation artifact indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxfile_eventHigh304Free2023-06-16