Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows BITS Client Job Downloads From Uncommon Remote TLDs
Alerts on BITS transfers (EventID 16403) to remote domains with uncommon or suspicious TLD patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsbits-clientMedium121Free2022-06-10Windows Process Execution via Squirrel.exe Proxy Arguments
Identifies Windows executions of Squirrel.exe/Update.exe that use processStart-style arguments to launch other processes.
Nasreddine Bencherchali (Nextron Systems), Karneades / Markus Neis, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium272Free2022-06-09Windows Process: Squirrel.exe Using Download/Update Flags to Fetch Files
Alert on Squirrel.exe/update.exe runs with --download/--update flags and HTTP in the command line.
Nasreddine Bencherchali (Nextron Systems), Karneades / Markus Neis, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium151Free2022-06-09Windows Process Creation: Mftrace.exe Child Process Execution
Alerts on child processes spawned by Mftrace.exe, which can be abused to execute arbitrary binaries on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium163Free2022-06-09Windows: Process creation involving VSIISExeLauncher.exe with -p and -a arguments
Flags Windows launches of VSIISExeLauncher.exe with "-p" and "-a" parameters, consistent with potential arbitrary binary execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium166Free2022-06-09Windows: Adplus.exe Execution with Memory Dump and Command Options
Alerts on Windows executions of Adplus.exe with memory-dump and inline command parameters.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2022-06-09Windows File Creation of .diagcab Packages
Alerts on newly created Windows .diagcab files that may indicate malicious packaging or exploitation.
frack113, Huntrule TeamWindowsfile_eventMedium176Free2022-06-08Windows: ISO Image Opened by Archiver Utilities (WinRAR/7-Zip/PeaZIP)
Alerts when WinRAR/7-Zip/PeaZIP spawns ISO image tools, a pattern consistent with archive-delivered ISO payloads.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-06-07Windows Process Creation: Renamed Plink (plink.exe) with SSH Port Forwarding Flags
Alerts on renamed Plink executions using SSH port forwarding flags in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh359Free2022-06-06Windows Office Startup Folder File Creation with Uncommon Extension
Detects unusual-extension files created in Word/Excel startup folders on Windows, potentially supporting automatic Office loading.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh315Free2022-06-05Windows rundll32 Locks Workstation via user32.dll LockWorkStation
Flags cmd-launched rundll32.exe calling user32.dll LockWorkStation to lock the user workstation.
frack113, Huntrule TeamWindowsprocess_creationMedium363Free2022-06-04Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
frack113, Huntrule TeamWindowsps_scriptLow111Free2022-06-04Windows Process Creation: Renamed msdt.exe Execution
Flags Windows process creation where OriginalFileName is msdt.exe and the executable appears to be a renamed copy.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh294Free2022-06-03Python Process Spawning a Pretty TTY via pty.spawn on Windows
Flags Windows python executions whose command line imports pty and calls pty.spawn to create a pseudo-terminal.
Nextron Systems, Huntrule TeamWindowsprocess_creationHigh4010Free2022-06-03Windows Process Creation: BrowserCore.exe Renamed Execution for Azure Token Theft
Flags renamed BrowserCore.exe executions by matching OriginalFileName while the process image ends with BrowserCore.exe.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh437Free2022-06-02