Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,442 rules
Windows Process Execution of F# Interpreters (Fsi.exe, FsiAnyCpu.exe)
Flags execution of F# interpreter binaries fsi.exe and fsianycpu.exe on Windows.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsprocess_creationMedium81Free2022-06-02Windows File Events: wmiexec Default Output File Creation (__1<9 digits>.<1-7 digits>)
Detects Windows file creation matching wmiexec default output filename patterns in admin share and drive paths.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventCritical297Free2022-06-02Windows Office Startup Folder File Drop for Persistence via Office Documents
Alerts when Office documents/templates are created in Word/Excel startup folders on Windows, suggesting persistence attempts.
Max Altgelt (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2022-06-02Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Alert when sdiagnhost.exe launches high-risk child processes like PowerShell or CMD, excluding selected benign-like command patterns.
Nextron Systems, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh122Free2022-06-01Windows msdt.exe Execution with Suspicious Parent Process
Alerts when msdt.exe runs under common command-and-script or utility parent processes on Windows.
Nextron Systems, Huntrule TeamWindowsprocess_creationHigh254Free2022-06-01Windows Process Creation: wfc.exe Execution for Workflow Command-line Compiler Abuse
Alerts on execution of wfc.exe by matching process image and OriginalFileName in Windows process creation logs.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsprocess_creationMedium476Free2022-06-01VisualUiaVerifyNative.exe Execution on Windows
Alerts when VisualUiaVerifyNative.exe is launched on Windows, a potential application-control bypass binary.
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule TeamWindowsprocess_creationMedium161Free2022-06-01Windows Registry: Custom URL Protocol Handler Persistence via HKCR\ Protocol Registration
Alerts on HKCR registry set activity registering a new custom URL protocol handler, excluding Microsoft-style ms- protocols.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium255Free2022-05-30Windows msdt.exe / ms-msdt Handler Arbitrary Command Execution Attempts
Alerts on Windows executions of msdt.exe with command-line indicators suggesting arbitrary command execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2022-05-29Windows Registry: OneDriveStandaloneUpdater.exe URL From UpdateOfficeConfig for Proxy Download
Alerts on registry settings that redirect OneDrive update URL retrieval from UpdateOfficeConfig for internet downloads.
frack113, Huntrule TeamWindowsregistry_setHigh188Free2022-05-28PowerShell: Signed UtilityFunctions.ps1 Loading Managed DLL via Proxy Execution
Flags PowerShell command lines referencing UtilityFunctions.ps1 with RegSnapin usage consistent with managed DLL proxy execution.
frack113, Huntrule TeamWindowsprocess_creationMedium121Free2022-05-28Windows: Pubprn.vbs Script Proxy Execution via script: Command Line
Flags command-line executions referencing Pubprn.vbs with 'script:' indicative of proxy script command execution on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium152Free2022-05-28Windows PowerShell detects obfuscated Net.Webclient casing anomalies in command line
Alerts when PowerShell command lines contain encoded obfuscation patterns referencing Net.Webclient with anomalous casing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh229Free2022-05-24Windows PowerShell Process Command Lines With Encoded Command Flags
Alerts on PowerShell (pwsh) command lines using encoded command flags and encoded-looking substrings, excluding gc_worker.exe-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-05-24Windows: Jlaive In-Memory Assembly Execution via Copied Batch Executable
Detects chained cmd/.bat staging that uses xcopy plus PowerShell/pwsh and attrib +h/+s to run a .bat.exe payload associated with Jlaive.
Jose Luis Sanchez Martinez (@Joseliyo_Jstnk), Huntrule TeamWindowsprocess_creationMedium153Free2022-05-24