Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows: Small Sieve IoC File Creation via AppData and Typo Filename Indicators
Alerts on Windows file events with Small Sieve filename typo/path indicators or the OutlookDataPlus.txt IOCs.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh113Free2023-05-19Windows WerFault ReflectDebugger Registry Key Value Targeting
Flags registry set events targeting WerFault ReflectDebugger under Windows Error Reporting Hangs for potential persistence abuse.
X__Junior, Huntrule TeamWindowsregistry_setHigh141Free2023-05-18PowerShell Certificate Export Cmdlets in Windows Process Creation
Flags PowerShell command lines invoking certificate export cmdlets (Export-PfxCertificate/Export-Certificate) on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium408Free2023-05-18Windows WWlib.DLL sideloading via Office process loading behavior
Alert on Windows image-load events where winword-associated processes load wwlib.dll outside expected Office paths.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium183Free2023-05-18Windows CreateStreamHash: Suspicious Embedded File Download Indicators via .zip TLD
Flags Windows downloads indicating .zip/ plus ':Zone' in target filenames for risky executable or script extensions.
Florian Roth (Nextron Systems), Huntrule TeamWindowscreate_stream_hashHigh162Free2023-05-18Windows Process Creation: findstr.exe Searches for 'passwords' Keywords in Multiple Languages
Flags findstr.exe command lines searching password keywords across multiple languages.
Josh Nickels, Huntrule TeamWindowsprocess_creationMedium70Free2023-05-18Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments
Flags rundll32.exe launches with command-line ordinal obfuscation patterns.
Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-05-17Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2023-05-17Windows Process Creation: cloudflared Tunnel Execution with Config and Credentials Flags
Alerts on Windows processes running cloudflared tunnels with config and token/credential flags.
Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium351Free2023-05-17Windows: Detect cloudflared tunnel cleanup command execution
Flags Windows executions of cloudflared with tunnel cleanup and connector/config parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium332Free2023-05-17AWS CloudTrail: S3 Browser Creates IAM User or Access Key
Alerts on CloudTrail IAM CreateUser/CreateAccessKey actions initiated by a "S3 Browser" user agent.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh131Free2023-05-17AWS CloudTrail: S3 Browser creates inline IAM policy with default bucket placeholder
Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh123Free2023-05-17AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile
Flags CloudTrail IAM GetLoginProfile and CreateLoginProfile activity initiated by an S3 Browser user agent.
daniel.bohannon@permiso.io (@danielhbohannon), Huntrule TeamAwscloudtrailHigh471Free2023-05-17Windows Registry: Internet Explorer DisableFirstRunCustomize Set via Explorer or ie4uinit
Alerts on Windows registry writes to Internet Explorer DisableFirstRunCustomize that change first-run wizard customization states.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium315Free2023-05-16Windows LiveKD Kernel Memory Dump Attempt via "-m" Flag
Flags LiveKD executions with the "-m" option that may trigger kernel memory dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-05-16