Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry: Suspicious Keyboard Layout Preload in User Session
Detects user-hive registry changes that preload Persian (Iranian) or Vietnamese keyboard layouts under Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setMedium342Free2019-10-12Windows Screen Capture via psr.exe (Problem Steps Recorder) Execution
Flags psr.exe launched with /start or -start, indicating potential user screen and click recording.
Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationMedium83Free2019-10-12Windows OpenWith.exe Launches Another Binary via /c
Flags Windows OpenWith.exe executions that include '/c', indicating it launched another binary.
Beyu Denis, oscd.community (rule), @harr0ey (idea), Huntrule TeamWindowsprocess_creationHigh42Free2019-10-12Windows Devtoolslauncher.exe LaunchForDeploy Executes a Specified Binary
Alerts when devtoolslauncher.exe runs with LaunchForDeploy, indicating it may launch another binary on Windows.
Beyu Denis, oscd.community (rule), @_felamos (idea), Huntrule TeamWindowsprocess_creationHigh337Free2019-10-12Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical111Free2019-10-11PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh60Free2019-10-08PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh307Free2019-10-08Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders
Alerts on registry Run key writes originating from Downloads or temporary Outlook/IE directories on Windows.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poude (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh113Free2019-10-01Suspicious Windows Program Execution from Outlook Temporary Internet Files Folder
Alerts on process executions whose image path points to Outlook temporary files (Content.Outlook).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2019-10-01Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2019-09-26Windows fsutil.exe Suspicious USN Journal and File Zeroing Parameters
Alerts when fsutil.exe is run with USN journal deletion/creation or setZeroData-style file zeroing commands.
Ecco, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationHigh137Free2019-09-26Windows Registry: Enable WDigest UseLogonCredential (Use clear-text logon credential setting)
Flags registry writes that enable WDigest UseLogonCredential, turning on potential clear-text credential storage.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_setHigh203Free2019-09-12Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Alerts when wsmprovhost.exe is seen as a process or parent process, indicating remote PowerShell via WinRM.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium60Free2019-09-12Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents
Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.
Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements), Huntrule TeamWindowsprocess_creationLow91Free2019-09-12Windows Named Pipe Created for PowerShell PSHost Instance
Alerts on named pipe creation with a \PSHost prefix, indicating PowerShell host-related activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowspipe_createdInformational40Free2019-09-12