Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Creation: Python Executed with the -c Inline Code Flag
Flags Windows executions of python.exe with -c inline code, excluding common installer/baseline and VS Code contexts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium171Free2023-01-02Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Alerts on Windows process launches whose command line includes well-known malicious PowerShell commandlet names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2023-01-02Windows: Inline PHP execution via php.exe -r flag
Flags Windows process executions of php.exe with the inline "-r" code execution flag.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2023-01-02Windows Process Creation: Perl Inline Code Execution via -e/-E
Flags command-line usage of perl.exe with inline execution (-e) on Windows process creation events.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium205Free2023-01-02Windows EVTX File Creation in Non-Standard Locations
Flags creation of .evtx files outside typical Windows event log directories to support event log evasion or export.
D3F7A5105, Huntrule TeamWindowsfile_eventMedium3510Free2023-01-02Windows Process Creation: Uncommon Child Processes Spawned by DefaultPack.EXE
Alerts when DefaultPack.exe spawns an uncommon child process, indicating potential proxy execution on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium436Free2022-12-31Windows Image Load: coregen.exe Potential DLL Sideloading
Identifies potential DLL sideloading when coregen.exe loads DLLs outside expected system and Silverlight locations.
frack113, Huntrule TeamWindowsimage_loadMedium418Free2022-12-31Windows SharpLDAPmonitor HackTool Execution via Image Name and Credential/DC Flags
Flags SharpLDAPmonitor execution on Windows with LDAP-related command-line parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2022-12-30Windows: ssh.exe Used as Proxy/Local Command Launcher via ProxyCommand and LocalCommand
Detects Windows executions of ssh.exe that use ProxyCommand and PermitLocalCommand/LocalCommand to launch proxied or local commands.
frack113, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium259Free2022-12-29Windows: PowerShell Enable-WindowsOptionalFeature Enables Suspicious Optional Features
Alerts on PowerShell Enable-WindowsOptionalFeature used with -Online to enable listed optional features.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium505Free2022-12-29Windows: Detect unregmp2.exe used to proxy-launch wmpnscfg.exe with /HideWMP
Flags Windows executions of unregmp2.exe with /HideWMP, indicating proxy-style launching behavior.
frack113, Huntrule TeamWindowsprocess_creationMedium354Free2022-12-29Windows: Detect runexehelper.exe used to proxy-launch other programs
Flags process executions where runexehelper.exe is the parent, suggesting proxy-based launching of other programs.
frack113, Huntrule TeamWindowsprocess_creationMedium142Free2022-12-29Windows RDP Session Hijacking via tscon.exe from System Integrity
Flags tscon.exe executions on Windows running at System integrity, indicating potential RDP session hijacking.
"@juju4, Huntrule Team"Windowsprocess_creationMedium185Free2022-12-27Windows PowerShell Token Obfuscation via Process Command Line
Identifies Windows PowerShell command lines using token obfuscation patterns, common in Invoke-Obfuscation.
frack113, Huntrule TeamWindowsprocess_creationHigh2210Free2022-12-27SharpImpersonation Tool Execution on Windows
Flags execution of SharpImpersonation.exe on Windows when command-line parameters indicate token impersonation activity.
Sai Prashanth Pulisetti @pulisettis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-12-27