Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
PowerShell Script Reading Files and Resolving DNS Host Entries
Identifies PowerShell scripts that read files, resolve DNS host entries, and output results to disk.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium1810Free2023-05-05Windows DLL Sideloading: libcurl.dll Loaded by gup.exe from Uncommon Location
Alerts when gup.exe loads libcurl.dll from a path that doesn’t match the excluded Notepad++ GUP.exe location.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium415Free2023-05-05Windows: File creation of a Procmon-named .sys driver by non-procmon processes
Alerts when a procmon-named .sys driver is created by a process other than procmon.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium132Free2023-05-05Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh465Free2023-05-05Windows Suspicious File Creation in C:\PerfLogs with Executable/Script Extensions
Alerts on creation of potentially malicious file types in C:\PerfLogs\ on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventMedium131Free2023-05-05Windows: File Creation of NTDS.DIT (Active Directory Database)
Flags creation of an ntds.dit file on Windows, an Active Directory database artifact often associated with credential access.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventLow172Free2023-05-05Windows Process: sqlcmd.exe Querying Veeam Backup Databases
Flags sqlcmd.exe command lines querying Veeam backup database objects associated with repository and credential data.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium4310Free2023-05-04Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical415Free2023-05-04Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh122Free2023-05-04Proxy User-Agent starts with Base64-like prefixes associated with encoded client strings
Identifies proxy requests with User-Agent values starting with known Base64-encoded prefixes.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWebproxyMedium234Free2023-05-04Windows PowerShell Script Block Matching POWERTRASH Behavior Indicators
Detects PowerShell ScriptBlock text containing POWERTRASH-related in-memory and dynamic execution indicators on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2023-05-04PowerShell ScriptBlock Launching wscript.exe via PowerHold-like Code Patterns on Windows
Flags PowerShell ScriptBlock text that writes staged bytes in APPDATA and launches wscript.exe.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptHigh161Free2023-05-04Windows PowerShell Script File Creation Matching FIN7-Style Filenames
Alerts on Windows PowerShell script drops named host_ip.ps1 or ending with _64refl.ps1.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh112Free2023-05-04Windows process execution: WerFault.exe launched from WinSxS by services.exe
Alerts on WerFault.exe running from WinSxS when spawned by services.exe on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh177Free2023-05-04Windows Process Creation: Detect jpinst.exe/jpsetup.exe Installation Binary Indicators
Detects execution of jpinst.exe or jpsetup.exe on Windows, indicative of SNAKE installation activity.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh226Free2023-05-04