Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Registry: New ODBC Driver Registration via ODBCINST.INI
Flags Windows registry changes that add ODBC driver entries under ODBCINST.INI, with exclusions for specific known benign cases.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow123Free2023-05-23Windows: Odbcconf.EXE INSTALLDRIVER Use With Missing .dll Target
Flags odbcconf.exe running INSTALLDRIVER when the driver argument lacks a .dll extension.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-05-23Windows: BlueSky ransomware-related file and share access events
Alerts on Windows file/share access involving .bluesky and "DECRYPT FILES BLUESKY" artifact naming tied to BlueSky activity.
j4son, Huntrule TeamWindowssecurityHigh131Free2023-05-23Windows: Uncommon Child Process Spawned by Odbcconf.EXE
Alert on unusual child processes spawned from odbcconf.exe, which may indicate indirect execution abuse.
Harjot Singh @cyb3rjy0t, Huntrule TeamWindowsprocess_creationMedium454Free2023-05-22Windows Process Execution of Odbcconf.exe with -f Response File Flag
Alerts on Odbcconf.exe being run with -f to load a response file, excluding runonce-driven executions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2023-05-22Windows Odbcconf.EXE Response File Execution via -f Flag
Flags Windows executions of Odbcconf.EXE using -f to load a .rsp response file.
Kirill Kiryanov, Beyu Denis, Daniil Yugoslavskiy, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium81Free2023-05-22Windows: Suspicious Odbcconf.EXE REGSVR usage with non-DLL-suffixed target
Flags odbcconf.exe launched with REGSVR while the target lacks a .dll extension on Windows process creation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh453Free2023-05-22Windows: Odbcconf.exe used to register a DLL via REGSVR
Flags odbcconf.exe executions using REGSVR to register a DLL, a regsvr32-equivalent technique often abused by attackers.
Kirill Kiryanov, Beyu Denis, Daniil Yugoslavskiy, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-05-22Windows Process Execution: odbcconf.exe with DLL in Suspicious Path
Flags odbcconf.exe process launches when the command line references DLL-related paths in suspicious Windows locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2023-05-22Windows: Detect Odbcconf.exe INSTALLDRIVER DLL Installation via Process Command Line
Alerts when odbcconf.exe is run with INSTALLDRIVER and a .dll, indicating potential malicious ODBC driver DLL installation.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2023-05-22Windows Suspicious Non-Browser Network Traffic to api.telegram.org
Alerts on Windows network connections to api.telegram.org by processes other than common web browsers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium131Free2023-05-19Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters
Flags Windows Event 4661 activity indicating password policy enumeration (ReadPasswordParameters on Security Account Manager).
Zach Mathis, Huntrule TeamWindowssecurityMedium167Free2023-05-19Windows Registry Run Key Persistence Using Small Sieve Typo Value Strings
Flags registry Run-key writes on Windows with Small Sieve-specific typo and executable detail strings in value data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh178Free2023-05-19Proxy HTTP GET to api.telegram.org with chat_id and text com/ (Small Sieve C2 behavior)
Alerts on proxy HTTP GET requests to api.telegram.org containing a specific chat_id and com/ prefix consistent with C2 behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyCritical112Free2023-05-19Windows Process Creation: Detects Command-Line Ending With '.exe Platypus'
Alerts when a Windows process command line ends with '.exe Platypus', matching a Small Sieve indicator.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh341Free2023-05-19