Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,301 rules
Windows regsvr32 Usage of /i Without /n Flag
Alerts on regsvr32.exe invocations using /i: without the usually paired /n flag.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium176Free2019-07-13Windows: Explorer factory invocation causing process tree break
Alerts on process creation command lines showing explorer.exe factory and /root usage consistent with an explorer-based process tree break.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @gott_cyber, Huntrule TeamWindowsprocess_creationMedium84Free2019-06-29Windows Process Creation: Executable Extension Masquerading with .exe After Decoy Extension
Alerts on Windows processes whose paths/command lines use misleading double extensions ending in .exe to cloak executable execution.
Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2019-06-26Windows Security Log LSASS Access by Non-Computer Account Process
Alerts on suspicious LSASS access attempts (4663/4656) targeting lsass.exe by non-system processes using flagged access masks.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium3710Free2019-06-20Windows Security Event 4662 Detects DPAPI Domain Backup Key Extraction from Domain Controllers
Detects read access to LSA secret DPAPI domain backup key objects in Windows Event ID 4662.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh123Free2019-06-20Windows: Suspicious userinit.exe Child Process Creation
Alerts when userinit.exe spawns an atypical child process, excluding known benign explorer and netlogon command-line patterns.
Florian Roth (Nextron Systems), Samir Bousseaden (idea), Huntrule TeamWindowsprocess_creationMedium71Free2019-06-17Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh286Free2019-06-15Windows Process Creation: Suspicious Renamed Binary Masquerading as Common Tools
Flags Windows executions where Sysmon OriginalFileName matches common tools but the process Image name ends differently.
Matthew Green @mgreen27, Ecco, James Pemberton @4A616D6573, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationMedium149Free2019-06-15Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Flags Windows 4624 successful logons consistent with Pass-the-Hash activity using NtLmSsp or seclogo.
Dave Kennedy, Jeff Warren (method) / David Vassallo (rule), Huntrule TeamWindowssecurityMedium30Free2019-06-14Windows Process Creation: Renamed jusched.exe Execution via Java Scheduler Names
Alerts when Java Update Scheduler descriptions are used to execute a process ending with \jusched.exe on Windows.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh238Free2019-06-04Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh405Free2019-05-22WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
Patryk Prauze - ING Tech, Huntrule TeamWindowsprocess_accessHigh239Free2019-05-20Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
Alec Costello, Huntrule TeamWindowsps_scriptHigh248Free2019-05-16Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.
Markus Neis, Huntrule TeamWindowsnetwork_connectionHigh71Free2019-05-15Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh127Free2019-04-20