Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
185 rules
Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Flags Word (WINWORD.EXE) spawning csc.exe, a suspicious execution pattern observed in some exploit chains.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical41Free2017-09-15Windows rundll32 execution matching ZxShell function and remote disk strings
Alerts on rundll32.exe command lines containing zxFunction and RemoteDiskXXXXX indicative of ZxShell execution.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationCritical52Free2017-07-20Windows WCE wceaux.dll File Access via Security Event 4656/4663
Identifies Windows Security event activity involving access to the wceaux.dll library file.
Thomas Patzke, Huntrule TeamWindowssecurityCritical92Free2017-06-14Windows Registry Event: Pandemic implant key path contains null Instance
Detects registry activity targeting CurrentControlSet\services\null\Instance, associated with Windows implant persistence staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical81Free2017-06-01Windows Service Creation: ServiceName javamtsup (Event ID 4697)
Flags Windows Security Event 4697 when a service named "javamtsup" is installed, indicating potential persistence.
Florian Roth (Nextron Systems), Daniil Yugoslavskiy, oscd.community (update), Huntrule TeamWindowssecurityCritical112Free2017-03-27