Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows DLL Sideloading Suspicion via edputil.dll Image Load
Alerts on edputil.dll image loads occurring outside standard Windows system directories, suggesting possible DLL side-loading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh112Free2023-06-09Windows DLL Sideloading Indicators: 7za.dll Loaded from Non-Program Files Paths
Alerts when a process loads 7za.dll from a non-Program Files path, indicating potential DLL sideloading.
X__Junior, Huntrule TeamWindowsimage_loadLow176Free2023-06-09Linux sshd Logs: Flag Failed Curve25519 Key Generation Indicative of libSSH CVE-2023-2283 Attempts
Alerts on sshd log entries with 'Failed to generate curve25519 keys' that may indicate CVE-2023-2283 libssh bypass attempts.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsshdMedium2710Free2023-06-09Windows ClickOnce Loads Unsigned or Expired Signed Modules from User Apps Path
Alerts when a ClickOnce app loads a module from Apps\2.0 that is unsigned or has an expired signature.
"@SerkinValery, Huntrule Team"Windowsimage_loadMedium258Free2023-06-08Windows Registry COM InProcServer32 Hijack via PSFactory CLSID Default Value
Detects suspicious modifications to a PSFactory COM InProcServer32 (Default) registry value that may enable COM-based persistence.
BlackBerry Threat Research and Intelligence Team - @Joseliyo_Jstnk, Huntrule TeamWindowsregistry_setHigh452Free2023-06-07Windows Code Integrity: Kernel Module Loaded Without WHQL Requirements (Event 3082/3083)
Alerts when Code Integrity logs show loaded kernel modules failing WHQL compliance (Event 3082/3083), excluding selected VMware drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh82Free2023-06-06Windows Code Integrity Operational: Unsigned Image Loaded
Alerts on Windows Code Integrity detecting that an unsigned image was loaded (Event ID 3037).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh111Free2023-06-06Windows Code Integrity Unsigned Kernel Module Loaded (Event ID 3001)
Alerts on Windows Code Integrity reporting an unsigned kernel module load via Event ID 3001.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh289Free2023-06-06Windows Code Integrity: Revoked Signed Image Loaded (Event 3032/3035)
Alerts on Code Integrity events showing a revoked signed image was loaded, including debugger-allowed cases.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh143Free2023-06-06Windows Code Integrity blocks image load when signing certificate is revoked (Event ID 3036)
Alerts on Windows Code Integrity Event ID 3036 when image loads are blocked because the signing certificate is revoked.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh122Free2023-06-06Windows Code Integrity: Revoked Kernel Driver Loaded (Event 3021/3022)
Alerts when Windows Code Integrity reports a revoked kernel driver/module loaded (including debugger-allowed cases) via Event IDs 3021/3022.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh179Free2023-06-06Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Flags Code Integrity Operational events where Windows blocks loading a revoked (untrusted) driver certificate.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh147Free2023-06-06Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
Alerts on Windows Code Integrity Event ID 3104 when a disallowed file is blocked for protected processes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscodeintegrity-operationalHigh113Free2023-06-06Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript
Alerts on suspicious renamed AutoIt2/AutoIt3 execution based on command-line parameters plus known hashes and original file names.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2023-06-04Webserver GET Requests to MOVEit Human2.aspx Paths Indicative of CVE-2023-34362 Web Shell Attempts
Alerts on GET requests to human2.aspx/_human2.aspx paths associated with MOVEit CVE-2023-34362 exploitation attempts.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—webserverHigh459Free2023-06-03