Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows process command line matches SNAKE installer argument pattern
Alerts on Windows process command lines containing a 64-hex then 16-hex CLI argument sequence consistent with a malware installer pattern.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2023-05-04Windows Non-Browser Process Network Connection to api.notion.com
Alerts when a non-browser Windows process connects to api.notion.com, excluding common browsers and the Notion desktop app.
Gavin Knapp, Huntrule TeamWindowsnetwork_connectionLow100Free2023-05-03Windows Service Creation via SCM (Event ID 7045) with svchost.exe and specific service names
Alerts on Windows 7045 service creations where ImagePath contains svchost.exe and service names match Name/msupdate/msupdate2.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh282Free2023-05-02Windows Registry User Profile Creation: ANONYMOUS _DomainUser_ Entries in ProfileList
Alerts on ProfileList registry writes indicating a new user profile with 'ANONYMOUS' and '_DomainUser_' markers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh141Free2023-05-02Windows svchost.exe Loading newdev.dll from AppData Roaming (Potential Persistence)
Alerts on svchost.exe loading newdev.dll from AppData\Roaming, an unusual pattern consistent with stealthy persistence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh2910Free2023-05-02Windows Suspicious Non-Browser Network Connections to Google API Endpoints
Alerts on suspicious Windows processes connecting to Google API hostnames, excluding common browsers and known benign apps.
Gavin Knapp, Huntrule TeamWindowsnetwork_connectionMedium458Free2023-05-01Windows Process Creation: svchost.exe with msupdate/alg Service Flags
Alerts on svchost.exe started with specific -k command-line flags consistent with suspicious persistence activity.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical153Free2023-04-30Windows rundll32 Cleanup Export Execution via msupdate Service Host (ColdSteel)
Flags svchost.exe msupdate-style services spawning rundll32.exe to run cleanup-related exports.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical141Free2023-04-30Windows Process Execution with User Name "ANONYMOUS" from System32 or AppData
Alerts on Windows process executions where the user is marked "ANONYMOUS" and the parent path is in System32 or AppData.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh279Free2023-04-30Windows: Detect newdev.dll created in AppData\Roaming\ starting from C:\Users\
Detects creation of newdev.dll under a user’s AppData\Roaming directory for potential user-scoped persistence.
X__Junior (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3610Free2023-04-30Windows File Creation of dllhost.exe in Public Documents Used by COLDSTEEL RAT Variants
Flags creation of C:\users\public\Documents\dllhost.exe on Windows, matching an indicator seen in some COLDSTEEL RAT variants.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh91Free2023-04-30Windows Winlogon Outbound Network Connections to Public IPs
Flags outbound connections initiated by winlogon.exe to non-local public destination IPs on Windows.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, Huntrule TeamWindowsnetwork_connectionMedium101Free2023-04-28Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.
Christian Burkard (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh386Free2023-04-27Windows Security: Security-Enabled Global Group Deletion (Event ID 4730/634)
Alerts on Windows Security audit events indicating a security-enabled global group was deleted.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow171Free2023-04-26Windows Security Log: Member Removed from Security-Enabled Global Group
Flags Windows Security Log events showing a member was removed from a security-enabled global group.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityLow162Free2023-04-26