Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,353 rules
Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
NVISO, Huntrule TeamWindowsps_scriptHigh132Free2020-03-26Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
Teymur Kheirkhabarov, Harish Segar, Huntrule TeamWindowsprocess_creationHigh268Free2020-03-20PowerShell Downgrade Attempts via -Version 2 on Windows Process Creation
Alerts on PowerShell executions specifying a -Version 2 argument, consistent with potential downgrade attempts.
Harish Segar (rule), Huntrule TeamWindowsprocess_creationMedium281Free2020-03-20Windows Desktop.ini Accessed by Uncommon Process
Alerts when unexpected processes create or access Desktop.ini, which can be abused to change how Explorer displays folder contents.
Maxime Thiebaut (@0xThiebaut), Tim Shelton (HAWK.IO), Huntrule TeamWindowsfile_eventMedium92Free2020-03-19Windows Process Execution of .SettingContent-ms Command Line
Flags Windows processes whose command lines reference .SettingContent-ms, a potential trigger for setting-based execution.
Sreeman, Huntrule TeamWindowsprocess_creationMedium317Free2020-03-13Windows: Alert on Uncommon Child Process Executed from Appvlp.exe
Alerts on unusual child processes created by Appvlp.EXE on Windows, indicating potential command execution abuse.
Sreeman, Huntrule TeamWindowsprocess_creationMedium63Free2020-03-13Windows: Suspicious Execution of CSharp Interactive Console via PowerShell
Alerts when PowerShell launches csi.exe, indicating possible interactive .NET code execution.
Michael R. (@nahamike01), Huntrule TeamWindowsprocess_creationHigh142Free2020-03-08Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe
Alerts when svchost.exe launches mmc.exe with “-Embedding”, indicating potential MMC20 COM-based lateral movement.
"@2xxeformyshirt (Security Risk Advisors) - rule; Teymur Kheirkhabarov (idea), Huntrule Team"Windowsprocess_creationHigh437Free2020-03-04Windows Registry: TrustRecords key modification indicating macro-based initial access
Flags Windows registry writes to Security\Trusted Documents\TrustRecords, a signal consistent with macro-enabled initial access.
Antonlovesdnb, Trent Liffick (@tliffick), Huntrule TeamWindowsregistry_eventMedium61Free2020-02-19Windows: Office Application Loads VBE VBA DLLs via Image Load Events
Flags Office apps loading VBA-related VBE DLLs, a strong indicator of VBA macro execution.
Antonlovesdnb, Huntrule TeamWindowsimage_loadHigh132Free2020-02-19Windows Office Apps Loading .NET GAC MSIL DLLs via Image Load Events
Alerts when an Office app loads a .NET DLL from the GAC_MSIL directory.
Antonlovesdnb, Huntrule TeamWindowsimage_loadHigh70Free2020-02-19Windows: CLR DLL Loaded by Office Applications
Alerts when Excel, Word, Outlook, PowerPoint, Publisher, or OneNote loads clr.dll on Windows.
Antonlovesdnb, Huntrule TeamWindowsimage_loadMedium40Free2020-02-19Windows Office Apps Loading .NET Assembly DLLs from C:\Windows\assembly
Alerts when Office applications load DLLs from C:\Windows\assembly\ via image load events.
Antonlovesdnb, Huntrule TeamWindowsimage_loadMedium40Free2020-02-19Windows Process Memory Dump via comsvcs.dll using rundll32
Alert on rundll32 loading comsvcs.dll with arguments consistent with a full process memory dump.
Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2020-02-18Windows Process Creation: Sticky Keys Backdoor via sethc.exe Replacement
Flags forced replacement of C:\Windows\System32\sethc.exe with cmd.exe consistent with a Sticky Keys backdoor.
Sreeman, Huntrule TeamWindowsprocess_creationCritical116Free2020-02-18