Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Creation: tapinstall.exe Execution
Alerts on tapinstall.exe being executed on Windows, excluding known VPN driver installer paths.
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowsprocess_creationMedium427Free2019-10-24Windows Process Creation: Web Request Cmdlets and CLI Tools Usage
Alerts on Windows CommandLine usage of web request cmdlets/tools like Invoke-WebRequest, Invoke-RestMethod, curl, wget, and BITS transfer.
James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium73Free2019-10-24Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2019-10-24Windows Process Creation: SoundRecorder audio capture using /FILE
Flags SoundRecorder.exe launches that include /FILE, indicating potential audio capture on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationMedium63Free2019-10-24Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationLow81Free2019-10-24Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium72Free2019-10-24Windows netsh Trace Start Command Execution
Flags netsh.exe launched with "trace" and "start", commonly used to begin a network trace capture on Windows.
Kutepov Anton, oscd.community, Huntrule TeamWindowsprocess_creationMedium267Free2019-10-24Windows Mshta.exe Launching JavaScript via Command Line
Detects Mshta.exe executions where the command line includes "javascript".
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh326Free2019-10-24Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Alerts when Hwp.exe launches gbb.exe, a suspicious child process pattern on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2019-10-24Windows hh.exe Execution Triggered by .chm Command Line
Flags hh.exe being executed with a command line referencing a .chm file on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community, Huntrule TeamWindowsprocess_creationLow93Free2019-10-24Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
E.M. Anhaus, Tony Lambert, oscd.community, omkar72, Huntrule TeamWindowsprocess_creationMedium281Free2019-10-24Windows Execution of dnscat2 and iodine DNS Exfiltration/Tunneling Tools
Flags Windows execution of DNS tunneling/exfiltration tools identified by iodine.exe or dnscat2 in process creation events.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh203Free2019-10-24Windows Boot Configuration Tampering via bcdedit.exe
Flags bcdedit.exe commands that set boot status policy to ignore failures and disable recovery (recoveryenabled=no).
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh152Free2019-10-24Windows at.exe Interactive Job via Process Creation
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh173Free2019-10-24Windows PowerShell ScriptBlock Web Request Cmdlets and Command-Line Tools
Alerts when PowerShell script blocks reference web request and download cmdlets/commands, excluding a specific guest configuration path.
James Pemberton / @4A616D6573, Huntrule TeamWindowsps_scriptMedium142Free2019-10-24