Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
39 rules
Suspicious WMIC Execution from Anomalous Parent Process (via process_creation)
This rule detects wmic being spawned by an anomalous parent such as an Office application, browser or scripting host. Legitimate WMIC use rarely originates from these processes, so this parent-child relationship points to WMI being abused for execution or discovery following initial access.
HuntRule TeamWindowsprocess_creationMedium121Premium2026-08-06Linux Bun Runtime Execution: bun_environment.js via node-parent process
Flags /node-launched /bun executions running bun_environment.js with an external runner release download URL.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamLinuxprocess_creationHigh228Free2025-11-25Windows Setup16.EXE Execution Triggered by Custom .LST File
Flags Windows Setup16.EXE being invoked with ' -m ' from its system parent process, potentially tied to custom .lst-driven execution.
frack113, Huntrule TeamWindowsprocess_creationMedium203Free2024-12-01Windows: Suspicious rundll32 Execution of Non-DLL Extension via Living-off-the-Land Parent Processes
Flags rundll32.exe executions from common script parents where the command line references known drop locations but lacks standard extensions.
Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2024-01-26Windows PingCastle Execution From Suspicious Parent Processes
Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2024-01-11Windows Process Creation Signals for Pikabot System Discovery
Flags process-launch discovery commands (ipconfig/netstat/whoami) under rundll32 and Search host parent processes on Windows.
Andreas Braathen (mnemonic.io), Huntrule TeamWindowsprocess_creationHigh203Free2023-10-27DarkGate-related Autoit3.exe execution with suspicious parent process (Windows)
Alerts on AutoIt3.exe execution when spawned from cmd.exe, KeyScramblerLogon.exe, or msiexec.exe, excluding common legitimate install paths.
Micah Babinski, Huntrule TeamWindowsprocess_creationHigh153Free2023-10-15Windows Diskshadow.exe Child Process Execution
Alerts when Diskshadow.exe is the parent process of a newly created process on Windows.
Harjot Singh @cyb3rjy0t, Huntrule TeamWindowsprocess_creationMedium80Free2023-09-15Linux: Shell Execution from /tmp by Parent Process
Alert when a /tmp parent process spawns a shell (bash/sh/zsh/etc.), indicating likely staging and command execution.
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamLinuxprocess_creationHigh90Free2023-06-02Windows Scripting Engines Spawning regsvr32.exe via Parent Process Execution
Flags common script/command interpreters launching regsvr32.exe on Windows, a potential proxy execution behavior.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium161Free2023-05-26Windows Qakbot-associated Rundll32 execution via suspicious parent process and export strings
Flags rundll32.exe executions tied to Qakbot-style export strings when launched by script/cmd utilities.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical81Free2023-05-24Windows RDP client Mstsc.EXE launched from uncommon browser or email parent process
Alerts when mstsc.exe is spawned by a browser or Outlook, suggesting potential RDP access using a local .rdp file.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2023-04-18Windows: driverquery.exe Usage for Installed Driver Recon
Alerts when driverquery.exe (drvqry.exe) is launched by script-based parent processes to enumerate installed drivers.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2023-01-19Windows: Elevated PowerShell or CMD Spawned from Uncommon Parent Location
Alerts on elevated PowerShell/CMD executions whose parent process comes from uncommon Windows locations, indicating likely privilege escalation.
frack113, Tim Shelton (update fp), Huntrule TeamWindowsprocess_creationMedium182Free2022-12-05Windows: Suspicious Msbuild.exe execution from uncommon parent process
Alerts when Msbuild.exe runs under an unexpected parent process on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2022-11-17