Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,300 rules
Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
vburov, Huntrule TeamWindowsprocess_creationLow162Free2019-02-23Windows mshta.exe Execution Using Non-HTA File Extensions
Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.
Diego Perez (@darkquassar), Markus Neis, Swisscom (Improve Rule), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2019-02-22Windows: RDP Session Startup Folder Backdoor via tsclient Share Targeting Startup Path
Flags mstsc.exe activity writing to the Windows Startup folder, indicating potential RDP session backdoor placement.
Samir Bousseaden, Huntrule TeamWindowsfile_eventHigh153Free2019-02-21Windows svchost RDP via Reverse SSH Loopback Tunnel to 127.0.0.0/8:3389
Flags svchost.exe opening RDP (TCP 3389) connections to loopback, consistent with tunneled reverse access behavior.
Samir Bousseaden, Huntrule TeamWindowsnetwork_connectionHigh2310Free2019-02-16Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh133Free2019-02-16Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh484Free2019-02-11Windows PowerShell Script Block Matches Common Reflection and Injection Keywords
Alerts on PowerShell script block text containing reflection, dynamic assembly loading, and injection-related keywords.
Florian Roth (Nextron Systems), Perez Diego (@darkquassar), Tuan Le (NCSGroup), Huntrule TeamWindowsps_scriptMedium63Free2019-02-11Windows Process Creation: Suspicious calc.exe Command-Line Usage Outside System Locations
Alerts on suspicious calc.exe launches via command-line parameters or execution from non-standard Windows directories.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh425Free2019-02-09Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)
Alerts on bcdedit.exe executions with command-line options consistent with boot configuration tampering.
"@neu5ron, Huntrule Team"Windowsprocess_creationMedium112Free2019-02-07Windows Process Creation: Suspicious GUP.exe Execution from Non-Notepad++ Directories
Alerts on GUP.exe executions from unexpected directories on Windows, excluding known Notepad++ updater paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh168Free2019-02-06Windows Security Event 4616 for System Time Changes by Non-Service Accounts
Flags Windows Event 4616 system time changes when made by processes outside svchost.exe and common virtualization agents.
"@neu5ron, Huntrule Team"WindowssecurityLow82Free2019-02-05Windows Remote Thread Creation via CACTUSTORCH Using Script/Office/Rundll Host Images
Alerts on SysWOW64 remote thread creation initiated by script host or Office binaries consistent with CACTUSTORCH behavior.
"@SBousseaden (detection), Thomas Patzke (rule), Huntrule Team"Windowscreate_remote_threadHigh131Free2019-02-01Windows netsh.exe Used to Create RDP (3389) Port Forwarding
Flags netsh.exe executions that appear to set up RDP (3389) port forwarding.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationHigh302Free2019-01-29Windows netsh.EXE Adds Portproxy v4-to-v4 Forwarding Rule
Flags netsh.exe command lines that add portproxy v4-to-v4 forwarding rules on Windows.
Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium83Free2019-01-29Windows Firewall Rule Added via netsh.exe
Flags netsh.exe executions that add Windows firewall rules, indicating potential attacker-controlled network access changes.
Markus Neis, Sander Wiebing, Huntrule TeamWindowsprocess_creationMedium389Free2019-01-29