Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,460 rules
Windows: Process creation of UltraVNC VNCViewer (VNCViewer.exe)
Flags execution of UltraVNC VNCViewer.exe on Windows based on process creation metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium234Free2022-10-02Windows Registry: Modify User Shell Folders Startup Values for Persistence
Alerts on Windows Registry changes to User Shell Folders startup-related values that may be used to establish persistence.
frack113, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh393Free2022-10-01Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Flags w3wp.exe-launched commands matching China Chopper webshell execution patterns in Windows process creation logs.
Florian Roth (Nextron Systems), MSTI (query), Huntrule TeamWindowsprocess_creationHigh291Free2022-10-01Windows Suspicious Use of shutdown.exe to Log Off a User
Flags Windows executions of shutdown.exe with /l to log a user off.
frack113, Huntrule TeamWindowsprocess_creationMedium93Free2022-10-01Windows PDQ Deploy Console Execution
Alerts on Windows execution of PDQ Deploy Console (PDQDeployConsole.exe) based on process metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium261Free2022-10-01Windows RDP Registry Settings Modified to Zero
Alerts when RDP-related registry values are set to 0, potentially weakening remote access controls.
Samir Bousseaden, David ANDRE, Roberto Rodriguez @Cyb3rWard0g, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setMedium193Free2022-09-29Windows: AnyDesk Password Piped via CMD Using --set-password
Alerts on Windows command lines that echo a value and set an AnyDesk password non-interactively via --set-password.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium122Free2022-09-28Windows IIS connection string decryption via aspnet_regiis -pdf
Flags aspnet_regiis.exe runs that target IIS connectionStrings for decryption using -pdf.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh144Free2022-09-28Windows: conhost.exe spawned by uncommon parent process
Alerts on conhost.exe launched by an uncommon parent process, using process creation parent image and command-line context.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium111Free2022-09-28PowerShell ScriptBlock Matching Invoke-Mimikatz Credential Dump Commands (Windows)
Detects PowerShell ScriptBlocks containing Mimikatz-like credential dump and certificate extraction command strings.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsps_scriptHigh112Free2022-09-28AnyDesk Windows: suspicious executable/DLL writes excluding gcapi.dll
Alerts when AnyDesk.exe or AnyDeskMSI.exe writes .dll/.exe files, excluding gcapi.dll.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh173Free2022-09-28Windows Process Creation: UAC bypass attempt via MMC Windows Firewall Snap-in hijack
Alerts when MMC launches WF.msc, a possible UAC bypass snap-in hijack pattern, excluding WerFault.exe-related cases.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium2910Free2022-09-27Windows Process Creation: SSH Port-Forwarding Commands Targeting RDP (3389)
Flags Windows command lines using SSH port-forwarding switches that also reference RDP port :3389.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium111Free2022-09-27Windows ImagingDevices.exe Spawns Unusual Parent/Child Processes
Alerts when ImagingDevices.exe participates in atypical process parent/child chains on Windows, based on process creation telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh273Free2022-09-27Windows: Unusual Child Process Spawn by dns.exe
Alerts when dns.exe launches an unexpected child process other than conhost.exe.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-27