Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry Persistence via UserInitMprLogonScript Value
Detects registry value name containing "UserInitMprLogonScript", which may indicate logon-script persistence setup.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowsregistry_setMedium82Free2019-01-12Windows userinit.exe Spawns Uncommon Child Processes
Alerts when userinit.exe starts an unexpected child process during logon, suggesting potential persistence via modified logon behavior.
Tom Ueltschi (@c_APT_ure), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh399Free2019-01-12Windows Command Line Logon Script Persistence via UserInitMprLogonScript
Alerts when a Windows process command line references UserInitMprLogonScript, a potential logon-script persistence indicator.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowsprocess_creationHigh173Free2019-01-12PowerShell Executed From AppData on Windows (Command Line Indicators)
Flags PowerShell command lines that include AppData paths (Local/Roaming), indicating possible user-profile script execution.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium82Free2019-01-09Windows Process Creation: Outlook EnableUnsafeClientMailRules Security Setting Enabled
Flags Windows process command lines that reference Outlook’s EnableUnsafeClientMailRules security setting.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2018-12-27Windows Process Creation: SecurityXploded PasswordDump.exe Execution
Alerts on Windows executions of SecurityXploded PasswordDump.exe based on process metadata and filename.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical382Free2018-12-19Windows Process Creation: Rubeus HackTool Execution Indicators
Flags Windows process executions of Rubeus.exe when command lines include Kerberos attack-related actions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical156Free2018-12-19Windows Process Creation: Command Line Obfuscation via Escape Characters
Identifies Windows process command lines containing escape-character URL obfuscation patterns.
juju4, Huntrule TeamWindowsprocess_creationMedium122Free2018-12-11Windows Remote Thread Injection Indicators via Process StartAddress Suffixes
Flags Windows CreateRemoteThread events with StartAddress suffixes 0B80, 0C7C, or 0C88.
Olaf Hartong, Florian Roth (Nextron Systems), Aleksey Potapov, oscd.community, Huntrule TeamWindowscreate_remote_threadHigh365Free2018-11-30Windows: Suspicious Executable Downloads Missing File Metadata Fields
Alerts when a process launches from Downloads with missing/placeholder file metadata (Description, FileVersion, Product, or Company).
Markus Neis, Sander Wiebing, Huntrule TeamWindowsprocess_creationMedium131Free2018-11-22Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Flags PowerShell script blocks containing Base64 strings matching known shellcode markers.
David Ledbetter (shellcode), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh113Free2018-11-17Windows: Potential Kerberoasting SPN Enumeration via setspn.exe
Detects Windows setspn.exe runs with SPN query command-line parameters that may indicate Kerberoasting preparation.
Markus Neis, keepwatch, Huntrule TeamWindowsprocess_creationMedium415Free2018-11-14Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2018-10-30Windows: Local user account creation via net.exe or net1.exe
Alerts on net.exe/net1.exe launching with "user" and "add" to create local accounts on Windows.
Endgame, JHasenbusch (adapted to Sigma for oscd.community), Huntrule TeamWindowsprocess_creationMedium40Free2018-10-30Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Flags PowerShell (powershell.exe/pwsh) process executions with command-line indicators consistent with XOR/obfuscated scripting.
Sami Ruohonen, Harish Segar, Tim Shelton, Teymur Kheirkhabarov, Vasiliy Burov, oscd.community, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium257Free2018-09-05