Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows dns.exe Deletes Files with Unexpected Targets
Alerts when dns.exe deletes any file other than dns.log on Windows.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_deleteHigh82Free2022-09-27Windows: Unusual File Modification by dns.exe
Alert on dns.exe changing files other than dns.log, which can indicate suspicious or compromised system activity.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_changeHigh423Free2022-09-27Windows: w32tm.exe Timer/Delay Usage via stripchart Parameters
Flags w32tm.exe executions using stripchart delay-related parameters that can support timed automation on Windows.
frack113, Huntrule TeamWindowsprocess_creationHigh482Free2022-09-25Windows UltraViewer Desktop App Execution
Alerts on execution of UltraViewer Desktop on Windows based on executable metadata in process creation events.
frack113, Huntrule TeamWindowsprocess_creationMedium4210Free2022-09-25Windows Process Creation: NetSupport Client Configurator (PCICFGUI.EXE)
Alerts on execution of NetSupport Client Configurator (PCICFGUI.EXE) on Windows via process metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium163Free2022-09-25Windows: Suspicious Parent Process Spawning cmd.exe
Alerts on cmd.exe executions that have a suspicious/atypical parent process among listed Windows binaries.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium274Free2022-09-21Windows Process Creation: Renamed createdump.exe Used for .dmp Memory Dumps
Flags renamed createdump.exe executions on Windows that use full dump flags and produce .dmp files.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-09-20Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh81Free2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
Tim Rauch, frack113, Huntrule TeamWindowsps_scriptHigh204Free2022-09-20Windows Process Creation: Remote Utilities renamed to rutserv.exe or rfusclient.exe
Alerts on suspicious Windows execution tied to "Remote Utilities" where the image does not match known rutserv.exe/rfusclient.exe names.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium71Free2022-09-19Windows: Detects NetSupport RAT client32.exe execution using Imphash and filename metadata
Flags renamed NetSupport RAT client32.exe launches on Windows using a specific Imphash and file metadata, while filtering a matching image path.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2022-09-19Windows: RURAT (Remote Utilities) Executed From Unusual Path
Alerts on Remote Utilities RURAT executables running outside the typical Program Files install paths on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium231Free2022-09-19Windows: NetSupport client32.exe Executed From Non-Standard Directory
Flags NetSupport client32.exe launched from locations outside Program Files on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium162Free2022-09-19Windows: Detect winPEAS privilege escalation reconnaissance execution
Flags Windows executions of winPEAS/PEASS-ng based on image name and command-line discovery options and release download indicators.
Georg Lauenstein (sure[secure]), Huntrule TeamWindowsprocess_creationHigh408Free2022-09-19Windows Registry: Tampering ChannelAccess Permissions for WINEVT Event Channels
Alerts on registry updates to WINEVT ChannelAccess that set SDDL permissions granting elevated access to event channels.
frack113, Huntrule TeamWindowsregistry_setHigh322Free2022-09-17