Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Scheduled Task Creation Using System Process Names
Flags schtasks.exe /create commands whose arguments reference common Windows system process names.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh319Free2025-02-05Windows Scheduled Task Creation via schtasks.exe with curl and PowerShell Command Line Indicators
Alerts on schtasks.exe task creation commands that simultaneously include curl download indicators and PowerShell execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium100Free2025-02-05Windows Process Creation: NimScan.exe Execution via Known File Hashes
Alerts on Windows execution of NimScan.exe when process image and known IMPHASH values match.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium201Free2025-02-05Windows MMC Executes Files with RLO-Reversed Extensions in Process Command Line
Alerts when mmc.exe runs with command lines containing RLO-style reversed filename patterns ending in .msc.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh446Free2025-02-05Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh130Free2025-02-05Windows MMC Loads Script Engine DLLs (vbscript.dll, jscript.dll, jscript9.dll)
Alerts when mmc.exe loads vbscript/jscript script engine DLLs, which can indicate script execution in a trusted process.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsimage_loadMedium484Free2025-02-05Windows file creation of executable/script files in \Users\Public
Alerts on Windows file creation in \Users\Public\ with potentially malicious script/binary extensions.
The DFIR Report, Huntrule TeamWindowsfile_eventHigh183Free2025-01-23Windows: Clfs.sys Loaded from Suspicious Process Image Paths
Alerts when clfs.sys is loaded by a process running from user/temp/perflogs-style suspicious paths on Windows.
X__Junior, Huntrule TeamWindowsimage_loadMedium272Free2025-01-20Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Detects registry changes to Windows Event Log ChannelAccess SDDL, which can limit event log visibility or control.
X__Junior, Huntrule TeamWindowsregistry_setHigh151Free2025-01-16Windows Process Creation: Microsoft QuickAssist.exe Execution
Alerts on execution of QuickAssist.exe by matching the process image ending with \QuickAssist.exe.
Muhammad Faisal (@faisalusuf), Huntrule TeamWindowsprocess_creationLow151Free2024-12-19Windows DNS Queries Initiated by QuickAssist.exe to remoteassistance.support.services.microsoft.com
Alerts when QuickAssist.exe performs DNS lookups for the Microsoft Quick Assist remote session endpoint.
Muhammad Faisal (@faisalusuf), Huntrule TeamWindowsdns_queryLow459Free2024-12-19Windows Setup16.EXE Execution Triggered by Custom .LST File
Flags Windows Setup16.EXE being invoked with ' -m ' from its system parent process, potentially tied to custom .lst-driven execution.
frack113, Huntrule TeamWindowsprocess_creationMedium203Free2024-12-01Windows Suspicious ShellExec_RunDLL via SHELL32.DLL Ordinal in Parent Command Line
Alert on Windows process starts where parent command line invokes SHELL32.DLL ShellExec_RunDLL using a matched ordinal and spawns suspicious binaries.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationHigh349Free2024-12-01Windows File Event: Detect RTLO Filename Extension Spoofing
Flags Windows filenames containing U+202E plus reversed extension strings that indicate potential extension spoofing.
Jonathan Peters (Nextron Systems), Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsfile_eventHigh202Free2024-11-17Windows Registry RunMRU PowerShell or WMIC Execution Command Indicators
Alerts on RunMRU registry entries showing PowerShell (encoding/invocation) or WMIC shadowcopy/process call usage.
Ahmed Farouk, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh191Free2024-11-01