Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
Windows DLL execution via register-cimprovider.exe with -path dll
Alerts on register-cimprovider.exe launching with -path pointing to a DLL.
Ivan Dyachkov, Yulia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium101Free2020-10-07Windows regedit.exe Imports Registry Keys From .reg File
Detects regedit.exe command lines importing registry keys from .reg files on Windows.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationMedium100Free2020-10-07Windows Registry Key Export via regedit.exe (-E) to File
Flags regedit.exe registry exports to files using the -E option, indicating potential discovery or exfiltration prep.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow173Free2020-10-07Windows Visual Basic vbc.exe Compiles to .obj via cvtres.exe Resource Converter
Alerts when vbc.exe spawns cvtres.exe during Windows VB command-line compilation activity.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsprocess_creationHigh151Free2020-10-07Windows: Process CallTrace using EditionUpgradeManager COM interface DLL
Alerts on process access events with call traces referencing editionupgrademanagerobj.dll via the EditionUpgradeManager COM interface.
oscd.community, Dmitry Uchakin, Huntrule TeamWindowsprocess_accessMedium112Free2020-10-07Windows regedit.exe exports a registry key into an alternate data stream
Flags regedit.exe executions where the process image ends with '\regedit.exe', consistent with exporting Registry data to an alternate data stream.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowscreate_stream_hashHigh193Free2020-10-07PowerShell Service Persistence via Registry ImagePath on Windows
Flags Windows registry service ImagePath entries that reference PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh202Free2020-10-06Windows: Winrm.vbs AWL bypass using attacker WsmPty.xsl/WsmTxt.xsl
Detects WinRM vbs execution with suspicious XSL formatting arguments, especially when the binary is outside System32/SysWOW64.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium354Free2020-10-06Windows: VBoxDrvInst.exe Invoked with driver/executeinf Parameters
Flags VBoxDrvInst.exe launched with parameters indicative of INF processing (driver/executeinf).
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium151Free2020-10-06Windows: Time Travel Debugging Utility (tttracer.exe) Process Execution
Alerts when tttracer.exe is the parent process of a spawned process on Windows.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsprocess_creationHigh408Free2020-10-06PowerShell Script Block WinAPI Calls Indicative of Injection or Token Abuse (Windows)
Detects PowerShell ScriptBlocks containing WinAPI function-name combinations consistent with injection and token manipulation.
Nasreddine Bencherchali (Nextron Systems), Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh173Free2020-10-06Windows UAC Bypass via dism.exe Loading Fake dismcore.dll
Alerts when dism.exe loads a dismcore.dll that is not the expected System32 Dism DLL.
oscd.community, Dmitry Uchakin, Huntrule TeamWindowsimage_loadHigh404Free2020-10-06Windows Time Travel Debugging DLL Loads (ttdrecord/ttdwriter/ttdloader)
Flags Windows image loads of Time Travel Debugging Utility DLLs (tdrecord/tdwriter/tdloader), often abused for stealthy credential dumping.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsimage_loadHigh416Free2020-10-06Windows file events: Winrm.vbs payload XSL execution artifacts WsmPty.xsl/WsmTxt.xsl outside system folders
Alert on WsmPty.xsl/WsmTxt.xsl files written outside System32 and SysWOW64, consistent with WinRM VBScript misuse.
Julia Fomina, oscd.community, Huntrule TeamWindowsfile_eventMedium499Free2020-10-06Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
oscd.community, Natalia Shornikova, Huntrule TeamWindowscreate_remote_threadHigh215Free2020-10-06