Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Creation: SoftPerfect netscan.exe Network Scanner Execution
Alerts on execution of SoftPerfect Network Scanner (netscan.exe), a potential network reconnaissance tool.
"@d4ns4n_ (Wuerth-Phoenix), Huntrule Team"Windowsprocess_creationMedium187Free2024-04-25Windows RegAsm.exe Initiates Network Connection to Public IP
Alerts on RegAsm.exe initiating outbound connections to public (non-local/private) IP addresses.
frack113, Huntrule TeamWindowsnetwork_connectionMedium90Free2024-04-25Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh489Free2024-04-15Windows Registry: MaxMpxCt Value Changed (LanmanServer Parameters)
Monitors Windows registry updates to MaxMpxCt under LanmanServer parameters, impacting SMB connection request handling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow142Free2024-03-19Windows Execution of Renamed NirCmd.exe (nircmd.exe/nircmdc.exe) via PE OriginalFileName
Alerts when a process uses NirCmd.exe PE metadata while the executable name is renamed to nircmd.exe or nircmdc.exe.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2024-03-11Windows TeamViewer Remote Session Process Command Line Start
Flags TeamViewer_Desktop.exe being launched by TeamViewer_Service.exe with the expected IPCport and module parameters on Windows.
Josh Nickels, Qi Nan, Huntrule TeamWindowsprocess_creationLow332Free2024-03-11Windows File Creation of CrackMapExec-Related Temp Scripts and Output Files
Flags Windows file creation in C:\Windows\Temp\ with filenames and patterns associated with CrackMapExec artifacts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh445Free2024-03-11Windows Kerberos KDC Key Distribution Failure: No Suitable Encryption Key or Unsupported EType
Flags KDC TGS generation failures where no suitable encryption key intersects or the requested encryption type is unsupported.
"@SerkinValery, Huntrule Team"WindowssystemLow101Free2024-03-07Windows AD CS Denied Certificate Enrollment Requests (Event ID 53)
Alerts on CA-side denied certificate enrollment attempts in Windows via Microsoft-Windows-CertificationAuthority Event ID 53.
"@SerkinValery, Huntrule Team"WindowssystemLow364Free2024-03-07Windows Registry: SentinelOne Scan Context Menu Command Tampering by Non-SentinelOne Process
Alerts on registry modifications to SentinelOne scan context menu command entries not matching SentinelOne’s expected binary.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium72Free2024-03-06Windows Utility Loads Unsigned DLL (ImageLoad)
Flags DLL loads by InstallUtil/RegAsm/RegSvcs/regsvr32/rundll32 when the loaded DLL is unsigned or untrusted.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadMedium143Free2024-02-28Windows ScreenConnect Service Web Shell Execution via cmd.exe or csc.exe
Alert on ScreenConnect.Service.exe spawning cmd.exe or csc.exe, consistent with potential web shell execution on Windows.
Jason Rathbun (Blackpoint Cyber), Huntrule TeamWindowsprocess_creationHigh101Free2024-02-26Windows DNS Queries to update.onelaunch.com by OneLaunch.exe
Flags DNS requests to update.onelaunch.com from OneLaunch.exe on Windows.
Josh Nickels, Huntrule TeamWindowsdns_queryLow132Free2024-02-26Windows Suspicious Wget.exe Downloads From IP to Common Staging Paths
Flags wget.exe on Windows downloading from an IP over HTTP and saving to common staging/user directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2024-02-23Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2024-02-23