Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux network connections to ngrok tunneling endpoints
Alerts on Linux connections to ngrok tunnel domains, which may indicate tunneling-based C2 or exfiltration.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionHigh101Free2022-11-03Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh337Free2022-11-01Windows Scheduled Task Creation with GUID-like Task Name
Alerts on schtasks.exe creating scheduled tasks whose /TN value is wrapped GUID-like braces.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-10-31Windows Image Load: Uncommon VSSAPI DLL (vssapi.dll) by Suspicious Executables
Alerts when uncommon processes load vssapi.dll, a Shadow Copy–related DLL, using image load telemetry with path-based exclusions.
frack113, Huntrule TeamWindowsimage_loadHigh80Free2022-10-31Windows Remote Utilities Host Service Installation via Service Control Manager (EventID 7045)
Alerts on Windows Event 7045 when a "Remote Utilities - Host" service is installed from rutserv.exe -service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium141Free2022-10-31Windows Service Installation via NetSupport Manager (Event ID 7045)
Flags Windows service creation for NetSupport Manager Client32 (client32.exe) using Service Control Manager Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium162Free2022-10-31Windows: vsls-agent.exe Executed With --agentExtensionPath Suspicious Library Load
Flags vsls-agent.exe launched with --agentExtensionPath, suggesting a potentially suspicious external extension/library load.
bohops, Huntrule TeamWindowsprocess_creationMedium448Free2022-10-30Windows Process Command Lines Referencing Dot-Suffixed File Names
Alerts on Windows process executions whose command lines reference file-path strings ending with a dot.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh409Free2022-10-28Windows Named Pipe Creation: PAExec Default Pipe (\PAExec*)
Alerts on named pipe creations starting with "\PAExec" associated with PAExec default behavior on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspipe_createdMedium4610Free2022-10-26Windows Exchange PowerShell Cmdlet History Log Files Deleted
Flags deletion of Exchange PowerShell cmdlet history log files in the expected logging directory.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_deleteHigh161Free2022-10-26Windows Service Control Manager: Detect PAExec- service installation
Flags creation of PAExec-named Windows services with image paths under C:\WINDOWS via Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium269Free2022-10-26Windows: Registry change disabling MacroRuntimeScanScope runtime macro scanning
Flags Office registry updates that set MacroRuntimeScanScope to 0x00000000, disabling runtime scanning for enabled macros.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh1610Free2022-10-25Windows CLI Searching for JWT Strings (eyJ0eX / eyJhbGci) in Command Line
Flags Windows CLI token hunting when search utilities are used alongside JWT-like substrings in the command line.
Nasreddine Bencherchali (Nextron Systems), kagebunsher, Huntrule TeamWindowsprocess_creationMedium112Free2022-10-25Windows Image Load: Suspicious DLL Sideloading of dbghelp.dll
Alerts on dbghelp.dll being loaded from non-standard locations, indicating possible DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium101Free2022-10-25Windows Image Load Alerts for dbgcore.dll Sideloading
Alerts when dbgcore.dll is loaded from paths outside typical Windows directories, indicating possible DLL sideloading.
Nasreddine Bencherchali (Nextron Systems), Wietze Beukema (project and research), Huntrule TeamWindowsimage_loadMedium132Free2022-10-25