Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh363Free2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsfile_eventHigh162Free2020-10-29Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
Semanur Guneysu @semanurtg, oscd.community, Huntrule TeamWindowsprocess_creationHigh131Free2020-10-28Windows Registry Persistence via Office Test Startup Key
Flags registry changes to a Windows Office test startup key that may enable auto-execution of an arbitrary DLL.
omkar72, Huntrule TeamWindowsregistry_eventMedium456Free2020-10-25Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.
Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh292Free2020-10-23Windows Registry: Detect esentutl.exe activity under VSS service keys
Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh192Free2020-10-20Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsprocess_accessHigh181Free2020-10-20Windows DLL image load: credui.dll loaded by an uncommon process
Detects credui.dll or wincredui.dll being loaded by a process other than common system binaries.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium274Free2020-10-20Windows Event Log Detects Volume Shadow Copy Mounts (HarddiskVolumeShadowCopy, EventID 98)
Alerts when NTFS logs indicate a VSS (HarddiskVolumeShadowCopy) mount using EventID 98.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssystemLow478Free2020-10-20Windows Security: VSSAudit Event Source Registration (Event ID 4904/4905)
Alerts on VSSAudit security event source registration in Windows Security logs using Event IDs 4904/4905.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), Huntrule TeamWindowssecurityInformational3610Free2020-10-20Windows RunOnce Execution via runonce.exe With AlternateShellStartup and /r
Alerts on runonce.exe executing with /AlternateShellStartup and /r, consistent with configured RunOnce persistence behavior.
Avneet Singh @v3t0_, oscd.community, Christopher Peacock @SecurePeacock (updated), Huntrule TeamWindowsprocess_creationLow163Free2020-10-18Windows Process Execution and DLL Injection via Tracker.exe
Alerts on Tracker.exe executions with /d and /c command-line switches, excluding matching MSBuild child process patterns.
Avneet Singh @v3t0_, oscd.community, Huntrule TeamWindowsprocess_creationMedium162Free2020-10-18Windows: msdeploy.exe Execution with sync and RunCommand Parameters
Flags msdeploy.exe executions that include sync verb plus RunCommand source and destination parameters.
Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationMedium91Free2020-10-18Windows PowerShell Process Creation: COMPRESS OBFUSCATION with ASCII Encoding and DeflateStream
Flags PowerShell process creation command lines that use ASCII encoding plus compression/stream-reading patterns associated with obfuscation.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium426Free2020-10-18Windows: Dotnet.exe executes arbitrary DLL or csproj files
Alerts when dotnet.exe runs with .csproj or .dll arguments that may indicate loading or execution of untrusted .NET code.
Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationMedium81Free2020-10-18