Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows schtasks.exe Scheduled Task Creation by Non-Microsoft Office Integration
Alerts on schtasks.exe /create executions indicating scheduled task creation, with exclusions for Office integrator-related cases.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow247Free2019-01-16Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
juju4, Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium165Free2019-01-16Windows Process Execution from Unusual System Locations
Alerts on Windows process launches where the executable path is in or contains unusual directories like RECYCLER or SystemVolumeInformation.
juju4, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium334Free2019-01-16Windows Suspicious rasdial.exe Process Execution
Flags Windows process executions of rasdial.exe by matching process image names ending with rasdial.exe.
juju4, Huntrule TeamWindowsprocess_creationMedium185Free2019-01-16Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix), Huntrule TeamWindowsprocess_creationHigh306Free2019-01-16PowerShell Spawned by wscript.exe or cscript.exe on Windows
Flags PowerShell launched by Windows script engines (wscript/cscript), excluding specific Health Service State activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium129Free2019-01-16Windows PowerShell execution with download-related command line patterns
Alerts when PowerShell is started with command-line fragments indicative of downloading remote content.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationMedium102Free2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
John Lambert (rule), Huntrule TeamWindowsprocess_creationHigh121Free2019-01-16Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium215Free2019-01-16Windows Process Reconnaissance via net.exe Group/Account Queries
Alerts on Windows net.exe commands querying groups and accounts via domain/local group and /do-related flags.
Florian Roth (Nextron Systems), omkar72, @svch0st, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2019-01-16Windows Process Creation: Suspicious Children Spawned by mshta.exe
Flags mshta.exe spawning command, script, or utility processes commonly abused for executing malicious HTA payloads.
Michael Haag, Huntrule TeamWindowsprocess_creationHigh473Free2019-01-16Windows Java Process Started with Remote Debugging Enabled for Non-Localhost Connections
Identifies Java processes started with JDWP dt_socket remote debugging on a non-localhost address.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium344Free2019-01-16Windows Cmdkey.EXE Cached Credential Reconnaissance
Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.
jmallette, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2019-01-16Windows cmd.exe Command Line with URL and %AppData% Indicators
Alerts on cmd.exe executions whose command line includes a URL pattern (http/https) and %AppData%.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium40Free2019-01-16Windows WMI Event Subscription Creation (Sysmon Event 19/20/21)
Flags Sysmon-reported WMI event subscription filter/consumer activity (Event IDs 19–21) indicative of persistence.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowswmi_eventMedium71Free2019-01-12