Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,460 rules
Windows desktopimgdownldr.exe Remote File Download via /lockscreenurl:http
Flags desktopimgdownldr.exe executions that specify a remote lockscreen URL via /lockscreenurl:http.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium142Free2022-09-27Windows Process Creation: 7-Zip Compressing .dmp/.dump Files
Flags Windows executions of 7-Zip where the command line includes .dmp/.dump/.hdmp extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2610Free2022-09-27Windows dns.exe Deletes Files with Unexpected Targets
Alerts when dns.exe deletes any file other than dns.log on Windows.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_deleteHigh82Free2022-09-27Windows: Unusual File Modification by dns.exe
Alert on dns.exe changing files other than dns.log, which can indicate suspicious or compromised system activity.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_changeHigh423Free2022-09-27Windows: w32tm.exe Timer/Delay Usage via stripchart Parameters
Flags w32tm.exe executions using stripchart delay-related parameters that can support timed automation on Windows.
frack113, Huntrule TeamWindowsprocess_creationHigh482Free2022-09-25Windows UltraViewer Desktop App Execution
Alerts on execution of UltraViewer Desktop on Windows based on executable metadata in process creation events.
frack113, Huntrule TeamWindowsprocess_creationMedium4210Free2022-09-25Windows Process Creation: NetSupport Client Configurator (PCICFGUI.EXE)
Alerts on execution of NetSupport Client Configurator (PCICFGUI.EXE) on Windows via process metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium153Free2022-09-25Windows: Suspicious Parent Process Spawning cmd.exe
Alerts on cmd.exe executions that have a suspicious/atypical parent process among listed Windows binaries.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium274Free2022-09-21Windows Process Creation: Renamed createdump.exe Used for .dmp Memory Dumps
Flags renamed createdump.exe executions on Windows that use full dump flags and produce .dmp files.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-09-20Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
Tim Rauch, frack113, Huntrule TeamWindowsps_scriptHigh204Free2022-09-20Windows Process Creation: Remote Utilities renamed to rutserv.exe or rfusclient.exe
Alerts on suspicious Windows execution tied to "Remote Utilities" where the image does not match known rutserv.exe/rfusclient.exe names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2022-09-19Windows: Detects NetSupport RAT client32.exe execution using Imphash and filename metadata
Flags renamed NetSupport RAT client32.exe launches on Windows using a specific Imphash and file metadata, while filtering a matching image path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-09-19Windows: RURAT (Remote Utilities) Executed From Unusual Path
Alerts on Remote Utilities RURAT executables running outside the typical Program Files install paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium231Free2022-09-19Windows: NetSupport client32.exe Executed From Non-Standard Directory
Flags NetSupport client32.exe launched from locations outside Program Files on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2022-09-19