Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Creation: Suspicious calc.exe Command-Line Usage Outside System Locations
Alerts on suspicious calc.exe launches via command-line parameters or execution from non-standard Windows directories.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh435Free2019-02-09Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)
Alerts on bcdedit.exe executions with command-line options consistent with boot configuration tampering.
"@neu5ron, Huntrule Team"Windowsprocess_creationMedium122Free2019-02-07Windows Process Creation: Suspicious GUP.exe Execution from Non-Notepad++ Directories
Alerts on GUP.exe executions from unexpected directories on Windows, excluding known Notepad++ updater paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh188Free2019-02-06Windows Security Event 4616 for System Time Changes by Non-Service Accounts
Flags Windows Event 4616 system time changes when made by processes outside svchost.exe and common virtualization agents.
"@neu5ron, Huntrule Team"WindowssecurityLow92Free2019-02-05Windows Remote Thread Creation via CACTUSTORCH Using Script/Office/Rundll Host Images
Alerts on SysWOW64 remote thread creation initiated by script host or Office binaries consistent with CACTUSTORCH behavior.
"@SBousseaden (detection), Thomas Patzke (rule), Huntrule Team"Windowscreate_remote_threadHigh141Free2019-02-01Windows netsh.exe Used to Create RDP (3389) Port Forwarding
Flags netsh.exe executions that appear to set up RDP (3389) port forwarding.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationHigh302Free2019-01-29Windows netsh.EXE Adds Portproxy v4-to-v4 Forwarding Rule
Flags netsh.exe command lines that add portproxy v4-to-v4 forwarding rules on Windows.
Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium93Free2019-01-29Windows Firewall Rule Added via netsh.exe
Flags netsh.exe executions that add Windows firewall rules, indicating potential attacker-controlled network access changes.
Markus Neis, Sander Wiebing, Huntrule TeamWindowsprocess_creationMedium399Free2019-01-29Windows RDP Logon Using Localhost IP Address
Alerts on successful Windows logons (EventID 4624, LogonType 10) originating from localhost IPs.
Thomas Patzke, Huntrule TeamWindowssecurityHigh122Free2019-01-28Windows Registry: New Security Support Provider (SSP) added to LSA configuration
Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.
iwillkeepwatch, Huntrule TeamWindowsregistry_eventHigh132Free2019-01-18Windows Script Execution from User-Accessible Paths via WScript, CScript, or MSHTA
Alerts when WScript/CScript/MSHTA launches scripts or HTAs referenced from user and temp directories.
Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems), Dave Johnson, Huntrule TeamWindowsprocess_creationMedium72Free2019-01-16Windows Process Creation Attempt Using wmic.exe process call create
Alerts on Windows process creation attempts invoking wmic.exe with “process call create”, a common pattern for WMI-based execution.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Huntrule TeamWindowsprocess_creationMedium30Free2019-01-16Windows Suspicious Child Processes Spawned by Web Server Executables
Alerts when web server processes (e.g., nginx/httpd/caddy/php/tomcat) spawn suspicious Windows command/scripting executables.
Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2019-01-16Windows Process Execution From Uncommon or Sensitive Directories
Alerts on process executions from uncommon/sensitive Windows directories, excluding specific IBM and Citrix updater paths.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh132Free2019-01-16Windows Shim Database Persistence via sdbinst.exe with .sdb Payload
Alerts when sdbinst.exe runs and references a .sdb shim database, indicating potential shim-based persistence.
Markus Neis, Huntrule TeamWindowsprocess_creationMedium73Free2019-01-16