Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
Nasreddine Bencherchali (Nextron Systems), frack113 , X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-01Windows Process Creation: Suspicious ShellExec_RunDLL Command-Line Usage
Detects Windows command lines containing ShellExec_RunDLL along with other suspicious execution indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-09-01Windows net.exe Commands Manipulating Built-in Default Accounts (administrator/guest)
Flags net.exe/net1.exe process creation when command lines reference built-in Administrator/guest/default accounts with suspicious active/disable context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh284Free2022-09-01Windows Suspicious cmd.exe Launch After net use Mounting WebDAV Share
Flags cmd.exe command lines that mount an Internet WebDAV share with net use and immediately execute content from DavWWWRoot.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2022-09-01Windows Suspicious Process Execution Using GUID-Like Folder Names in %TEMP% or AppData
Hunts Windows processes whose command lines reference GUID-named folders in user AppData/Temp locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow100Free2022-09-01Windows schtasks.exe scheduled task creation or modification with high privileges on suspicious schedule types
Flags schtasks.exe commands that create/modify tasks to run on ONLOGON/ONSTART/ONCE/ONIDLE with SYSTEM or HIGHEST privileges.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3210Free2022-08-31Windows Process Creation: Wscript.Shell.Run keyword sequence in CommandLine
Alerts on Windows command lines containing Wscript.Shell.Run keyword sequence, suggesting script-driven shell execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2022-08-31Windows Process Creation: DefenderCheck.exe Execution (PUA/Signature Evasion)
Alerts on execution of DefenderCheck.exe/description to identify potential AV signature probing and evasion preparation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh421Free2022-08-30Windows Network Connection from Cmstp.EXE (Outbound)
Alerts on outbound network connections initiated by cmstp.exe, which is uncommon and may indicate process misuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh60Free2022-08-30Windows: cmstp.exe Loading DLL/OCX from Suspicious Paths
Alerts when cmstp.exe loads DLL/OCX from suspicious directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh82Free2022-08-30Windows RTCore64 Service Installation via Service Control Manager (Event ID 7045)
Alerts on creation of the RTCore64 Windows service via Service Control Manager Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh101Free2022-08-30Windows SharpLdapWhoami Execution via LDAP Whoami Methods
Flags execution of SharpLdapWhoami on Windows using LDAP-related whoami alternative method parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh178Free2022-08-29Potential DLL Sideloading via DeviceEnroller.exe Using /PhoneDeepLink
Alerts on deviceenroller.exe runs with /PhoneDeepLink, a potential DLL sideloading trigger referencing ShellChromeAPI.dll.
"@gott_cyber, Huntrule Team"Windowsprocess_creationMedium449Free2022-08-29Windows Registry Detection: COM TreatAs(Default) Hijacking
Flags registry changes to COM TreatAs(Default) keys, excluding common Office/ClickToRun and installer processes.
frack113, Huntrule TeamWindowsregistry_setMedium92Free2022-08-28Windows Process Creation: nimgrab.exe Execution (Nim Tool Download Behavior)
Alerts on execution of nimgrab.exe on Windows when hashes match known indicators.
frack113, Huntrule TeamWindowsprocess_creationHigh163Free2022-08-28