Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,442 rules
Windows PowerShell Execution of Obfuscated One-Liner for In-Memory Module Download
Alerts on Windows PowerShell one-liners containing an obfuscated in-memory download/execute pattern from an HTTP URL.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh132Free2022-05-09Windows: WerFault.exe/wer.dll File Creation in Uncommon Locations
Alerts on newly created WerFault.exe or wer.dll in non-standard locations, suggesting potential DLL hijacking activity.
frack113, Huntrule TeamWindowsfile_eventMedium323Free2022-05-09Windows Security Event 5379: Opened Password-Protected ZIP from Outlook Attachment
Flags Windows events where a password-protected ZIP is opened from Outlook Temporary Internet Files.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh152Free2022-05-09Windows Security: Password-Protected ZIP Opened with Suspicious Filename Indicators
Alerts when Windows opens password-protected ZIP contents with filenames commonly tied to invoices, orders, payments, and deliveries.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh217Free2022-05-09Windows Security Event 5379: Password-Protected ZIP Opened
Flags Windows EventID 5379 indicating a password-protected ZIP archive was opened.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium132Free2022-05-09Windows: ie4uinit.exe Used from Non-Standard Current Directory
Flags ie4uinit.exe runs whose CurrentDirectory is outside expected system paths, indicating potential LOLBIN misuse.
frack113, Huntrule TeamWindowsprocess_creationMedium415Free2022-05-07Windows Process Creation: Ilasm.EXE Used to Compile IL to EXE/DLL
Alerts when Ilasm.EXE is run with /exe or /dll to compile IL into a Windows binary.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium142Free2022-05-07Windows Process Creation: Cobalt Strike module/command strings entered in cmd.exe
Alerts when cmd.exe command lines include Cobalt Strike module/command strings.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh444Free2022-05-06Windows Process Command Line: Accidental Cobalt Strike Commands in cmd.exe
Flags cmd.exe executions whose command lines include known Cobalt Strike command terms.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh60Free2022-05-06Windows Process Creation: Suspicious Child Processes Spawned by regsvr32.exe
Alerts when regsvr32.exe spawns suspicious child processes like PowerShell, mshta, or scripting utilities.
elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-05-05Windows: Registry Set by Rundll32 for Screen Saver Execution via SCRNSAVE.EXE
Flags Windows registry sets where Rundll32 points SCRNSAVE.EXE to a .scr file.
Jose Luis Sanchez Martinez (@Joseliyo_Jstnk), Huntrule TeamWindowsregistry_setMedium162Free2022-05-04Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Detects rundll32.exe launching davclnt.dll DavSetCookie with HTTP and spoolss/srvsvc pipe parameters associated with NTLM coercion.
Elastic (idea), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-05-04Windows Registry: Service configured with image path in suspicious public/temp folders
Detects Windows service ImagePath pointing to Users\Public, Perflogs, ADMIN$, or Temp based on registry_set events.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsregistry_setHigh141Free2022-05-02Windows: PrintBrm.exe ZIP extraction or creation via command-line parameters
Flags PrintBrm.exe executions that include '-f' and '.zip', consistent with ZIP creation or extraction behavior.
frack113, Huntrule TeamWindowsprocess_creationHigh132Free2022-05-02Windows JScript Compiler (jsc.exe) Process Execution
Identifies execution of jsc.exe (JScript Compiler) from Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationLow195Free2022-05-02