Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Devil Bait-like Recon via Wscript/Cmd with APPDATA Redirection
Flags cmd.exe launched by wscript.exe to redirect discovery output into %APPDATA%\Microsoft (.xml/.txt) using system enumeration commands.
Nasreddine Bencherchali (Nextron Systems), NCSC (Idea), Huntrule TeamWindowsprocess_creationHigh2210Free2023-05-15Uncommon Windows Processes Writing .txt/.xml in AppData\Roaming\Microsoft
Flags creation of .txt/.xml files in AppData\Roaming\Microsoft by schtasks.exe, wscript.exe, or mshta.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-05-15Windows RoboForm DLL Sideloading via ImageLoaded roboform.dll/roboform-x64.dll
Alerts on loaded roboform*.dll modules on Windows when module loading is not matched to expected RoboForm binaries.
X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium447Free2023-05-14Potential C2 HTTP Traffic via Goofy Guineapig User-Agent to static.tcplog.com (Proxy Logs)
Flags proxy HTTP requests with a specific Chrome-like User-Agent to static.tcplog.com, consistent with potential C2 traffic.
Nasreddine Bencherchali (Nextron Systems), Huntrule Team—proxyHigh161Free2023-05-14Windows Process Command Line Matching Goofy-Guineapig Backdoor Command Fragment
Alerts on Windows process command lines containing a specific non-interactive choice command often used in automation.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2023-05-14Windows File Indicators for Goofy Guineapig Malware IOCS
Flags Windows file events involving specific Goofy Guineapig backdoor indicator filenames.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh71Free2023-05-14Windows Certificate Export from Local Certificate Store (Event ID 1007)
Flags Windows events where a certificate is exported from the local certificate store via Certificate Services client telemetry.
Zach Mathis, Huntrule TeamWindowscertificateservicesclient-lifecycle-systemMedium113Free2023-05-13Windows CAPI2 Event 70: Certificate Private Key Acquired
Detects when Windows CAPI2 logs that a process acquired a certificate private key (EventID 70).
Zach Mathis, Huntrule TeamWindowscapi2Medium131Free2023-05-13Windows Excel Loads .XLL Add-in from Uncommon File Paths
Flags Excel loading .xll add-ins from uncommon directories based on image load paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium93Free2023-05-12Windows Excel Loads .XLL Add-In Files
Flags excel.exe loading a .XLL add-in module, an execution indicator for potential malicious add-in activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadLow90Free2023-05-12Windows: WinSxS .exe Creation Triggered by Non-System Process
Flags .exe creation in C:\Windows\WinSxS\ when the creating process is not from standard system directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium113Free2023-05-11Windows Registry Events Targeting SECURITY\Policy\Secrets\ (Snake Malware)
Alerts on Windows registry activity targeting the SECURITY\Policy\Secrets\n registry key suffix.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh379Free2023-05-11Windows Service Creation for WerFaultSvc Using C:\Windows\WinSxS\WerFault.exe
Alerts on Windows service creation of WerFaultSvc pointing to C:\Windows\WinSxS\...\WerFault.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemCritical121Free2023-05-10Windows Registry Persistence: Uncommon .wav OpenWithProgIds Value Creation
Flags registry value writes under .wav OpenWithProgIds with unusual naming that may indicate persistence behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium117Free2023-05-10Windows File Creation: Non-System WerFault.exe Created in WinSxS
Flags creation of C:\Windows\WinSxS\WerFault.exe by processes outside core Windows system directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh151Free2023-05-10