Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Command Line: Accidental Cobalt Strike Commands in cmd.exe
Flags cmd.exe executions whose command lines include known Cobalt Strike command terms.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh60Free2022-05-06Windows Raspberry Robin Execution via cmd.exe Parent and External-File Payload
Flags cmd.exe with /r from external media launching msiexec.exe /q that includes an HTTP/HTTPS payload URL.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh1810Free2022-05-06Windows: Raspberry Robin Command Execution via fodhelper.exe and rundll32/regsvr32
Flags Windows process-spawn chains where fodhelper.exe runs rundll32/regsvr32 with Raspberry Robin-style command-line patterns.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh388Free2022-05-06Windows Process Creation: Suspicious Child Processes Spawned by regsvr32.exe
Alerts when regsvr32.exe spawns suspicious child processes like PowerShell, mshta, or scripting utilities.
elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-05-05Windows: Registry Set by Rundll32 for Screen Saver Execution via SCRNSAVE.EXE
Flags Windows registry sets where Rundll32 points SCRNSAVE.EXE to a .scr file.
Jose Luis Sanchez Martinez (@Joseliyo_Jstnk), Huntrule TeamWindowsregistry_setMedium162Free2022-05-04Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Detects rundll32.exe launching davclnt.dll DavSetCookie with HTTP and spoolss/srvsvc pipe parameters associated with NTLM coercion.
Elastic (idea), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-05-04Linux: Detects Nimbuspwn-related exploit strings targeting CVE-2022-29799/CVE-2022-27800
Detects Linux keyword patterns suggesting Nimbuspwn-style traversal attempts via networkd-dispatcher error handling.
Bhabesh Raj, Huntrule TeamLinux—High349Free2022-05-04Windows Registry: Service configured with image path in suspicious public/temp folders
Detects Windows service ImagePath pointing to Users\Public, Perflogs, ADMIN$, or Temp based on registry_set events.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsregistry_setHigh141Free2022-05-02Windows: PrintBrm.exe ZIP extraction or creation via command-line parameters
Flags PrintBrm.exe executions that include '-f' and '.zip', consistent with ZIP creation or extraction behavior.
frack113, Huntrule TeamWindowsprocess_creationHigh132Free2022-05-02Windows JScript Compiler (jsc.exe) Process Execution
Identifies execution of jsc.exe (JScript Compiler) from Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationLow185Free2022-05-02Windows Service ImagePath Set to Non-Admin Controlled Directory
Alerts when a Windows service’s ImagePath is changed to a binary path under AppData or ProgramData.
Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setMedium60Free2022-05-02Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)
Flags process executions of gpresult.exe that request RSoP details using /z and /v on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium476Free2022-05-01Windows svchost.exe RDP (3389) Connections to HTTP/HTTPS Ports 80 or 443
Alerts when svchost.exe initiates from TCP 3389 to destination ports 80 or 443, consistent with possible RDP tunneling over web ports.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh182Free2022-04-29Windows: Detect ngrok Traffic Forwarded to Local RDP Port via TerminalServices Logs
Detects suspicious ngrok usage that forwards to the local RDP port using Windows TerminalServices-LocalSessionManager EventID 21.
Florian Roth (Nextron Systems), Huntrule TeamWindowsterminalservices-localsessionmanagerHigh111Free2022-04-29Windows rundll32.exe executing InstallScreenSaver via desk.cpl SCR File
Detects rundll32.exe launches with InstallScreenSaver behavior via desk.cpl, a screensaver execution technique.
Christopher Peacock @securepeacock, SCYTHE @scythe_io, TactiKoolSec, Huntrule TeamWindowsprocess_creationMedium194Free2022-04-28