Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,293 rules
Windows Process Creation with taskmgr.exe as Parent Process
Flags process creation where taskmgr.exe is the parent, excluding a few known benign child process images.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow72Free2018-03-13Windows WMI Script Event Consumer Execution via scrcons.exe
Flags scrcons.exe starting under svchost.exe, indicating WMI script event consumer execution that can support persistence.
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium217Free2018-03-07Windows WMI Persistence via wbemcons.dll Loaded by WmiPrvSE.exe
Identifies WmiPrvSE.exe loading wbemcons.dll, a behavior consistent with WMI command line event consumer persistence on Windows.
Thomas Patzke, Huntrule TeamWindowsimage_loadHigh83Free2018-03-07Windows WMI Persistence: Script Event Consumer File Writes (scrcons.exe)
Flags file writes performed by scrcons.exe, indicating potential WMI script event consumer persistence activity.
Thomas Patzke, Huntrule TeamWindowsfile_eventHigh439Free2018-03-07Windows Scheduled Task Creation via PowerShell Using schtasks.exe with ONLOGON/DAILY/ONIDLE/HOURLY
Flags PowerShell-launched schtasks.exe /Create commands matching default PowerSploit/Empire scheduled task persistence behavior.
Markus Neis, @Karneades, Huntrule TeamWindowsprocess_creationHigh261Free2018-03-06Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.
Roberto Rodriguez (source), Dominik Schaudel (rule), Huntrule TeamWindowssecurityHigh80Free2018-02-12Windows File Creation: QuarksPwDump Credential Dump (.dmp) in Temp\SAM-*
Flags creation of QuarksPwDump .dmp dump files in Temp with a SAM-* filename pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical313Free2018-02-10Windows msiexec Process Creation With Web URL Parameters
Alerts when msiexec is launched with command-line web URL indicators in its parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2018-02-09Windows System Binary Execution From Unusual Location (Process Creation)
Alerts when common Windows system binaries run from an uncommon directory rather than standard system locations.
Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh402Free2017-11-27Windows Security Event 4719 Audit Policy Changes indicate Windows auditing disabled
Flags Windows Event Auditing disabled indicators from Security Event ID 4719 with removed success/failure audit policy.
"@neu5ron, Nasreddine Bencherchali (Nextron Systems), Huntrule Team"WindowssecurityLow345Free2017-11-19Windows File Events: java.exe in AppData\Roaming\Oracle\bin Path with .exe and .vbs Artifacts
Alerts on Windows file events for suspicious java*.exe placement in AppData\Roaming\Oracle\bin and .vbs files containing "Retrive".
Florian Roth (Nextron Systems), Tom Ueltschi, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsfile_eventHigh435Free2017-11-10Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Flags USB device plug/unplug related Driver Frameworks User-Mode events using Windows event IDs 2003, 2100, and 2102.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver-frameworkLow3410Free2017-11-09Windows Named Pipe Creation Alert for Known Malicious Pipe Names
Alert on Windows named pipe creations where the PipeName matches known malware-associated pipe identifiers.
Florian Roth (Nextron Systems), blueteam0ps, elhoim, Huntrule TeamWindowspipe_createdCritical86Free2017-11-06Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Alerts on remote logons to admin-named accounts in Windows Security logs (4624, LogonType 10, Negotiate).
juju4, Huntrule TeamWindowssecurityLow314Free2017-10-29Windows Registry Key Created: Sysinternals EULA Acceptance
Flags registry writes indicating Sysinternals EULA acceptance via a TargetObject ending with \EulaAccepted.
Markus Neis, Huntrule TeamWindowsregistry_setLow80Free2017-08-28