Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,442 rules
Windows Process Execution via Squirrel.exe Proxy Arguments
Identifies Windows executions of Squirrel.exe/Update.exe that use processStart-style arguments to launch other processes.
Nasreddine Bencherchali (Nextron Systems), Karneades / Markus Neis, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium272Free2022-06-09Windows Process: Squirrel.exe Using Download/Update Flags to Fetch Files
Alert on Squirrel.exe/update.exe runs with --download/--update flags and HTTP in the command line.
Nasreddine Bencherchali (Nextron Systems), Karneades / Markus Neis, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium151Free2022-06-09Windows Process Creation: Mftrace.exe Child Process Execution
Alerts on child processes spawned by Mftrace.exe, which can be abused to execute arbitrary binaries on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium163Free2022-06-09Windows: Process creation involving VSIISExeLauncher.exe with -p and -a arguments
Flags Windows launches of VSIISExeLauncher.exe with "-p" and "-a" parameters, consistent with potential arbitrary binary execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium166Free2022-06-09Windows: Adplus.exe Execution with Memory Dump and Command Options
Alerts on Windows executions of Adplus.exe with memory-dump and inline command parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-06-09Windows File Creation of .diagcab Packages
Alerts on newly created Windows .diagcab files that may indicate malicious packaging or exploitation.
frack113, Huntrule TeamWindowsfile_eventMedium176Free2022-06-08Windows: ISO Image Opened by Archiver Utilities (WinRAR/7-Zip/PeaZIP)
Alerts when WinRAR/7-Zip/PeaZIP spawns ISO image tools, a pattern consistent with archive-delivered ISO payloads.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-06-07Windows Process Creation: Renamed Plink (plink.exe) with SSH Port Forwarding Flags
Alerts on renamed Plink executions using SSH port forwarding flags in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh359Free2022-06-06Windows Office Startup Folder File Creation with Uncommon Extension
Detects unusual-extension files created in Word/Excel startup folders on Windows, potentially supporting automatic Office loading.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh315Free2022-06-05Windows rundll32 Locks Workstation via user32.dll LockWorkStation
Flags cmd-launched rundll32.exe calling user32.dll LockWorkStation to lock the user workstation.
frack113, Huntrule TeamWindowsprocess_creationMedium363Free2022-06-04Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
frack113, Huntrule TeamWindowsps_scriptLow111Free2022-06-04Windows Process Creation: Renamed msdt.exe Execution
Flags Windows process creation where OriginalFileName is msdt.exe and the executable appears to be a renamed copy.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh294Free2022-06-03Python Process Spawning a Pretty TTY via pty.spawn on Windows
Flags Windows python executions whose command line imports pty and calls pty.spawn to create a pseudo-terminal.
Nextron Systems, Huntrule TeamWindowsprocess_creationHigh4010Free2022-06-03Windows Process Creation: BrowserCore.exe Renamed Execution for Azure Token Theft
Flags renamed BrowserCore.exe executions by matching OriginalFileName while the process image ends with BrowserCore.exe.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-06-02Windows Process Creation: Remote.exe Execution
Alerts on execution of remote.exe on Windows, which can be abused via a WinDbg/SDK binary for stealthy remote execution.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsprocess_creationMedium415Free2022-06-02