Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows file events matching SNAKE-related installer filename indicators
Flags Windows file events with target filenames ending in common SNAKE installer indicators like jpsetup.exe and jpinst.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow112Free2023-05-10Windows File Indicator: SNAKE Malware Kernel Driver Target File Comadmin.dat
Alerts on Windows file events involving C:\Windows\System32\Com\Comadmin.dat, an indicator tied to SNAKE kernel driver activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical243Free2023-05-10PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh235Free2023-05-09Windows: New PowerShell Module Files Created by Non-PowerShell Processes
Detects new PowerShell module files written into Modules directories by processes other than expected PowerShell hosts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium141Free2023-05-09Windows PowerShell Module File Creation via PowerShell Processes
Alert when PowerShell creates module-related files under WindowsPowerShell or PowerShell 7 module directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow152Free2023-05-09Windows PowerShell dropping a .ps1 script from powershell.exe or pwsh.exe
Alerts when PowerShell creates a dropped .ps1 script file on Windows, excluding common benign temp and test outputs.
frack113, Huntrule TeamWindowsfile_eventLow374Free2023-05-09Windows PowerShell Import-Module Cmdlet Execution
Flags PowerShell command lines containing Import-Module, indicating module loading into the current session.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow80Free2023-05-09System Informer Execution on Windows Process Creation
Alerts on Windows executions of SystemInformer.exe using matching filenames, metadata, and known hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium132Free2023-05-08Windows File Event: Flag Cyrillic Homoglyph Characters in Target Filename
Alerts on Windows file events with TargetFilename containing ASCII lookalike Unicode characters.
Micah Babinski, @micahbabinski, Huntrule TeamWindowsfile_eventMedium283Free2023-05-08Windows PUA System Informer Driver Load via SystemInformer.sys
Alerts on loading SystemInformer.sys as a Windows driver when matched against known System Informer SHA256 hashes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadMedium81Free2023-05-08Windows Process Command Line Matches Perfect Homoglyph Unicode Characters
Alerts when a Windows process command line includes Unicode homoglyphs that look like ASCII letters.
Micah Babinski, @micahbabinski, Huntrule TeamWindowsprocess_creationMedium162Free2023-05-07Windows ImageLoad of SolidPDFCreator.dll from Unexpected Paths
Alerts when SolidPDFCreator.dll is loaded from a non-standard process or path, consistent with potential DLL sideloading.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium51Free2023-05-07Okta FastPass blocks phishing authentication attempts via MFA
Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.
Austin Songer @austinsonger, Huntrule TeamOktaoktaHigh234Free2023-05-07Windows Wget.exe Downloads From File-Sharing Domains Matching Suspicious Output Flags
Flags wget.exe executions on Windows that download via HTTP from known file-sharing domains and write specific file extensions to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh425Free2023-05-05Windows curl.exe Downloads from File-Sharing Domains with Suspicious Output Extensions
Alerts on curl.exe downloading files over HTTP from file-sharing/content hosting domains, based on process command-line and executable context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2023-05-05