Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
PowerShell GzipStream Decompression Attempts on Windows
Detects Windows PowerShell commands using GZipStream and ::Decompress to decompress encoded Gzip data.
Hieu Tran, Huntrule TeamWindowsprocess_creationMedium123Free2023-03-13Windows Wazuh Platform DLL Side-Loading via ImageLoad of libwazuhshared.dll
Alerts on suspicious loading of Wazuh platform DLLs in Windows image load telemetry, excluding common Program Files and Mingw64 patterns.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadMedium151Free2023-03-13Windows Rcdll.dll DLL Sideloading via Image Load Path
Flags rcdll.dll loads from unexpected locations, excluding Visual Studio and Windows Kits directories.
X__Junior (Nextron Systems), Huntrule TeamWindowsimage_loadHigh133Free2023-03-13Windows AMSI.DLL Image Load by Uncommon Process Paths
Alerts when Amsi.dll is loaded by processes outside common Windows binaries and directories.
frack113, Huntrule TeamWindowsimage_loadLow120Free2023-03-12Windows 7-Zip Extracts Password-Protected Archives via 7z/7za/7zr
Flags 7-Zip (7z/7za/7zr) command lines that include -p with x extraction and -o output, indicating password-protected archive extraction.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow90Free2023-03-10Windows Process Creation: mshta/VBScript Launching PowerShell and Embedded Backdoor Logic
Alerts on Windows command lines combining mshta VBScript execution bypass, system survey WMI queries, and PowerShell HTTP/Base64 patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2023-03-10Windows Sysmon Configuration Update via Sysmon64 Command-Line
Flags execution of Sysmon binaries with '-c', indicating a Sysmon configuration update attempt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2023-03-09Linux Package Removal via yum, apt, dpkg, or rpm Commands
Detects package uninstall activity on Linux via yum, apt/apt-get, dpkg, or rpm based on command-line removal flags.
Tuan Le (NCSGroup), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamLinuxprocess_creationLow2510Free2023-03-09Windows Process Execution Matches Griffon Malicious Command-Line Pattern
Alerts on Windows process command lines containing a temp staging path plus jscript execution indicators and a .txt target.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical172Free2023-03-09Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh197Free2023-03-08Windows cmd.exe Reads Input from STDIN Using '<' Redirection
Flags cmd.exe invocations with '<' in the command line, indicating stdin/input redirection.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium402Free2023-03-07Linux Auditd: Unix Shell Configuration File Modification
Alerts when shell startup or login configuration files (system or user) are modified on Linux.
Peter Matkovski, IAI, Huntrule TeamLinuxauditdMedium183Free2023-03-06Linux firewall rule deletion via iptables, firewall-cmd, ufw, or nft
Flags EXECVE activity that removes Linux firewall rules using iptables, firewall-cmd, ufw, or nft.
IAI, Huntrule TeamLinuxauditdMedium3110Free2023-03-06Windows: Stop a Service with sc.exe via Process Creation (sc.exe stop)
Identifies sc.exe executions that include 'stop' to stop Windows services based on process creation and command line.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow192Free2023-03-05Windows PowerShell Stop-Service Used to Stop a Service
Flags PowerShell executions that include the Stop-Service cmdlet to stop a Windows service.
Jakob Weinzettl, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow111Free2023-03-05