Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows gpscript.exe Executes Group Policy Logon/Startup Scripts
Flags gpscript.exe running with /logon or /startup, suggestive of Group Policy script execution abuse.
frack113, Huntrule TeamWindowsprocess_creationMedium121Free2022-05-16Windows IEExec.EXE Download-and-Execute via Process Creation
Flags IEExec.exe executions that reference HTTP/HTTPS URLs for download-and-execute behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh346Free2022-05-16Windows: File Download via CertOC.exe Using -GetCACAPS HTTP
Flags CertOC.exe launched with -GetCACAPS and an http URL, indicating a remote file retrieval attempt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-05-16Windows Remote Thread Creation via Ttdinject.exe Proxy
Alerts on Windows create-remote-thread events initiated by Ttdinject.exe used as a proxy.
frack113, Huntrule TeamWindowscreate_remote_threadHigh122Free2022-05-16Windows Process Creation: reg.exe Adds Winlogon SpecialAccounts Userlist Value 0
Flags reg.exe command lines that add SpecialAccounts Userlist with /d 0 to hide accounts from the logon screen.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationMedium70Free2022-05-14Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)
Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical409Free2022-05-12Windows Service Creation for KrbRelayUp (KrbSCM)
Flags creation of the KrbSCM Windows service, a known KrbRelayUp installation artifact.
Sittikorn S, Tim Shelton, Huntrule TeamWindowssystemHigh3410Free2022-05-11Windows PowerShell Execution of Obfuscated One-Liner for In-Memory Module Download
Alerts on Windows PowerShell one-liners containing an obfuscated in-memory download/execute pattern from an HTTP URL.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh132Free2022-05-09Windows: WerFault.exe/wer.dll File Creation in Uncommon Locations
Alerts on newly created WerFault.exe or wer.dll in non-standard locations, suggesting potential DLL hijacking activity.
frack113, Huntrule TeamWindowsfile_eventMedium323Free2022-05-09Windows Security Event 5379: Opened Password-Protected ZIP from Outlook Attachment
Flags Windows events where a password-protected ZIP is opened from Outlook Temporary Internet Files.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh152Free2022-05-09Windows Security: Password-Protected ZIP Opened with Suspicious Filename Indicators
Alerts when Windows opens password-protected ZIP contents with filenames commonly tied to invoices, orders, payments, and deliveries.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh217Free2022-05-09Windows Security Event 5379: Password-Protected ZIP Opened
Flags Windows EventID 5379 indicating a password-protected ZIP archive was opened.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium132Free2022-05-09Windows: ie4uinit.exe Used from Non-Standard Current Directory
Flags ie4uinit.exe runs whose CurrentDirectory is outside expected system paths, indicating potential LOLBIN misuse.
frack113, Huntrule TeamWindowsprocess_creationMedium415Free2022-05-07Windows Process Creation: Ilasm.EXE Used to Compile IL to EXE/DLL
Alerts when Ilasm.EXE is run with /exe or /dll to compile IL into a Windows binary.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium142Free2022-05-07Windows Process Creation: Cobalt Strike module/command strings entered in cmd.exe
Alerts when cmd.exe command lines include Cobalt Strike module/command strings.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh434Free2022-05-06