Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows: Detect unregmp2.exe used to proxy-launch wmpnscfg.exe with /HideWMP
Flags Windows executions of unregmp2.exe with /HideWMP, indicating proxy-style launching behavior.
frack113, Huntrule TeamWindowsprocess_creationMedium354Free2022-12-29Windows: Detect runexehelper.exe used to proxy-launch other programs
Flags process executions where runexehelper.exe is the parent, suggesting proxy-based launching of other programs.
frack113, Huntrule TeamWindowsprocess_creationMedium142Free2022-12-29Windows RDP Session Hijacking via tscon.exe from System Integrity
Flags tscon.exe executions on Windows running at System integrity, indicating potential RDP session hijacking.
"@juju4, Huntrule Team"Windowsprocess_creationMedium185Free2022-12-27Windows PowerShell Token Obfuscation via Process Command Line
Identifies Windows PowerShell command lines using token obfuscation patterns, common in Invoke-Obfuscation.
frack113, Huntrule TeamWindowsprocess_creationHigh2110Free2022-12-27SharpImpersonation Tool Execution on Windows
Flags execution of SharpImpersonation.exe on Windows when command-line parameters indicate token impersonation activity.
Sai Prashanth Pulisetti @pulisettis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-12-27Windows: Execution of Htran/NATBypass HackTool Binaries or Tran/Slave CLI Flags
Detects Windows executions of htran.exe or lcx.exe and command lines containing -tran or -slave flags.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2022-12-27Windows PowerShell Inline Execution via File Reads and Raw Parameters
Alerts on PowerShell command lines that inline-execute content read from files using -raw.
frack113, Huntrule TeamWindowsprocess_creationMedium211Free2022-12-25Windows Process Creation: PowerShell COM CLSID Download Cradles
Alerts on PowerShell command lines using GetTypeFromCLSID with selected CLSIDs that may be used to download files via COM.
frack113, Huntrule TeamWindowsprocess_creationMedium214Free2022-12-25PowerShell ScriptBlock COM CLSID GetTypeFromCLSID Download Cradle Indicators
Alerts on PowerShell script blocks using GetTypeFromCLSID with specific CLSIDs indicative of COM-based download cradles.
frack113, Huntrule TeamWindowsps_scriptMedium301Free2022-12-25Windows PowerShell: In-Memory Assembly Loading via Reflection.Assembly
Flags PowerShell script blocks that reference [Reflection.Assembly]::load for potential in-memory assembly loading.
frack113, Huntrule TeamWindowsps_scriptMedium112Free2022-12-25Windows Process Execution: Suspicious AgentExecutor.exe PowerShell Launch with ExecutionPolicy Bypass
Detects AgentExecutor.exe command lines that trigger PowerShell script execution, including remediations and potentially bypassed ExecutionPolicy.
Nasreddine Bencherchali (Nextron Systems), memory-shards, Huntrule TeamWindowsprocess_creationHigh70Free2022-12-24Windows AgentExecutor.exe PowerShell Execution (ExecutionPolicy Bypass) Process Creation
Alerts on AgentExecutor.exe launches that pass -powershell/-remediationScript to run PowerShell (including bypass execution policy).
Nasreddine Bencherchali (Nextron Systems), memory-shards, Huntrule TeamWindowsprocess_creationMedium70Free2022-12-24Windows Process Copy/Move of Browser Credential Stores
Identifies Windows commands copying or moving browser user data directories consistent with credential theft.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium246Free2022-12-23Windows Process Creation: Suspicious X509Enrollment.CBinaryConverter Execution
Alerts on Windows command lines referencing X509Enrollment.CBinaryConverter with a specific GUID.
frack113, Huntrule TeamWindowsprocess_creationMedium384Free2022-12-23PowerShell FromBase64String Decoding of Base64 Gzip Content in Process Creation on Windows
Windows process command lines using PowerShell FromBase64String with MemoryStream and Gzip-like Base64 markers (H4sI) are flagged.
frack113, Huntrule TeamWindowsprocess_creationMedium412Free2022-12-23