Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,299 rules
Windows Registry: New Security Support Provider (SSP) added to LSA configuration
Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.
iwillkeepwatch, Huntrule TeamWindowsregistry_eventHigh122Free2019-01-18Windows Script Execution from User-Accessible Paths via WScript, CScript, or MSHTA
Alerts when WScript/CScript/MSHTA launches scripts or HTAs referenced from user and temp directories.
Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems), Dave Johnson, Huntrule TeamWindowsprocess_creationMedium52Free2019-01-16Windows Process Creation Attempt Using wmic.exe process call create
Alerts on Windows process creation attempts invoking wmic.exe with “process call create”, a common pattern for WMI-based execution.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Huntrule TeamWindowsprocess_creationMedium30Free2019-01-16Windows Suspicious Child Processes Spawned by Web Server Executables
Alerts when web server processes (e.g., nginx/httpd/caddy/php/tomcat) spawn suspicious Windows command/scripting executables.
Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2019-01-16Windows Process Execution From Uncommon or Sensitive Directories
Alerts on process executions from uncommon/sensitive Windows directories, excluding specific IBM and Citrix updater paths.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh132Free2019-01-16Windows Shim Database Persistence via sdbinst.exe with .sdb Payload
Alerts when sdbinst.exe runs and references a .sdb shim database, indicating potential shim-based persistence.
Markus Neis, Huntrule TeamWindowsprocess_creationMedium63Free2019-01-16Windows schtasks.exe Scheduled Task Creation by Non-Microsoft Office Integration
Alerts on schtasks.exe /create executions indicating scheduled task creation, with exclusions for Office integrator-related cases.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow237Free2019-01-16Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
juju4, Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium155Free2019-01-16Windows Process Execution from Unusual System Locations
Alerts on Windows process launches where the executable path is in or contains unusual directories like RECYCLER or SystemVolumeInformation.
juju4, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium334Free2019-01-16Windows Suspicious rasdial.exe Process Execution
Flags Windows process executions of rasdial.exe by matching process image names ending with rasdial.exe.
juju4, Huntrule TeamWindowsprocess_creationMedium185Free2019-01-16Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix), Huntrule TeamWindowsprocess_creationHigh306Free2019-01-16PowerShell Spawned by wscript.exe or cscript.exe on Windows
Flags PowerShell launched by Windows script engines (wscript/cscript), excluding specific Health Service State activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium119Free2019-01-16Windows PowerShell execution with download-related command line patterns
Alerts when PowerShell is started with command-line fragments indicative of downloading remote content.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationMedium82Free2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
John Lambert (rule), Huntrule TeamWindowsprocess_creationHigh121Free2019-01-16Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium185Free2019-01-16