Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows process creation: svchost.exe launched by sllauncher.exe for DLL side-loading
Flags AppData\Roaming-launched svchost.exe instances spawned by sllauncher.exe with -k, matching DLL side-loading execution behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical113Free2018-09-03Web server access to WebLogic keystore JavaScript webshell URLs
Flags web requests attempting to access JavaScript content within a WebLogic keystore path.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical271Free2018-07-22Cobalt Strike-style DNS Beaconing Queries (DNS)
Flags DNS queries with Cobalt Strike-style stage subdomain patterns used for covert beaconing.
Florian Roth (Nextron Systems), Huntrule TeamNetworkdnsCritical81Free2018-05-10Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Alerts on Windows service installation events for persistence-related scheduled services named SC Scheduled Scan or UpdatMachine.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssystemCritical91Free2018-03-23Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssecurityCritical216Free2018-03-23Windows Registry Persistence via UMe/UT Run Keys
Alerts on Windows registry changes to UMe/UT run key subpaths associated with persistence.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsregistry_eventCritical153Free2018-03-23Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Alerts when scheduled task and Service.exe processes launch autoit3.exe that runs nslookup TXT queries from a temp staging path.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationCritical229Free2018-03-23Windows Registry Image File Execution Options Debugger Backdoor (sethc.exe/utilman.exe/osk.exe)
Alerts on registry Debugger hijacks for Windows login/accessibility binaries using Image File Execution Options.
Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsregistry_eventCritical404Free2018-03-15Windows Backdoor Execution via Sticky Keys and Login-Screen Accessibility Tools
Flags winlogon.exe spawning command/script tools referencing login-screen accessibility binaries (sethc.exe, utilman.exe, osk.exe, etc.).
Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationCritical81Free2018-03-15WinWord spawning MicroScMgmt.exe indicative of CVE-2015-1641 exploitation on Windows
Alerts when Winword.exe starts MicroScMgmt.exe, matching a known CVE-2015-1641 exploitation behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical151Free2018-02-22Windows File Creation: QuarksPwDump Credential Dump (.dmp) in Temp\SAM-*
Flags creation of QuarksPwDump .dmp dump files in Temp with a SAM-* filename pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical313Free2018-02-10Windows Process Creation: svchost Running NavShExt.dll Deletion/Setting Commands
Alerts on svchost.exe process commands referencing cached NavShExt.dll deletion and execution markers consistent with Elise backdoor activity.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical396Free2018-01-31Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Flags Windows process creation where EQNEDT32.EXE is the parent, matching CVE-2017-11882 exploitation dropper behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical364Free2017-11-23Windows Named Pipe Creation Alert for Known Malicious Pipe Names
Alert on Windows named pipe creations where the PipeName matches known malware-associated pipe identifiers.
Florian Roth (Nextron Systems), blueteam0ps, elhoim, Huntrule TeamWindowspipe_createdCritical86Free2017-11-06Windows Named Pipe Creation Matching Suspected Turla Pipe Names
Alert on Windows named pipe creation when the PipeName matches Turla-associated strings.
Markus Neis, Huntrule TeamWindowspipe_createdCritical401Free2017-11-06