Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows DLL Sideloading: WmiApSrv Loads VMGuestLib.dll
Flags WmiApSrv.exe loading VMGuestLib.dll from VMware Tools vmStatsProvider on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadMedium327Free2022-12-01Windows DLL Sideloading via Loading ShellChromeAPI.dll
Alerts when Windows processes attempt to load ShellChromeAPI.dll, a DLL typically not present on systems.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh132Free2022-12-01Windows: Creation of Non-Existent System DLLs in System32 Paths
Alerts when targeted non-existent system DLL filenames are created in Windows system directories, indicating potential DLL hijacking setup.
Nasreddine Bencherchali (Nextron Systems), fornotes, Huntrule TeamWindowsfile_eventMedium151Free2022-12-01Windows: Gpg4win (GnuPG) Encrypt/Decrypt Command Using Suspicious File Paths
Flags Gpg4win/GnuPG file crypto commands using -passphrase with activity in temporary/public or suspicious Windows directories.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-11-30Windows PowerTool Process Execution
Flags Windows process creation events where PowerTool.exe/PowerTool64.exe is launched.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3810Free2022-11-29Windows Service Installation: TacticalRMM Agent Service (SCM Event 7045)
Flags Windows service installations that include tacticalrmm.exe and the TacticalRMM Agent Service using SCM Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium91Free2022-11-28Windows Service Control Manager: Mesh Agent Service Installation via Service Creation (7045)
Flags Windows Event ID 7045 service installations that reference MeshAgent.exe or “Mesh Agent”.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium342Free2022-11-28Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.
Janantha Marasinghe, Huntrule TeamAzuresigninlogsHigh81Free2022-11-27Windows UAC Bypass via Event Viewer RecentViews Path in Process Command Line
Flags Windows processes whose command lines reference Event Viewer RecentViews and use redirection, consistent with UAC bypass techniques.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2022-11-22Windows Registry NGenAssemblyUsageLog Key Tampering via .NET Usage Log Configuration
Alerts on registry modifications to the .NETFramework NGenAssemblyUsageLog key that can disrupt .NET Usage Log creation.
frack113, Huntrule TeamWindowsregistry_setHigh176Free2022-11-18Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Flags secedit.exe command lines used to export or configure Windows security policy.
Janantha Marasinghe, Huntrule TeamWindowsprocess_creationMedium133Free2022-11-18Windows: Suspicious Powercfg Execution Changing Lock/Video Standby Timeout
Detects powercfg.exe commands attempting to change standby/lock-related timeouts on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium82Free2022-11-18Windows: Suspicious Msbuild.exe execution from uncommon parent process
Alerts when Msbuild.exe runs under an unexpected parent process on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2022-11-17PowerShell Get-ADUser User Discovery and Data Export via File Output
Detects PowerShell Get-ADUser-based user enumeration combined with exporting results to files or output streams.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium91Free2022-11-17PowerShell Get-ADComputer Cmdlet Used for Computer Discovery and File Export
Flags PowerShell Get-ADComputer wildcard enumeration followed by writing exported computer data to a file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium80Free2022-11-17