Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Linux Process Creation: Interactive Bash With Suspicious Command-Line and Child Image
Flags interactive bash (bash -i) spawning likely malicious children with encoded execution or recon/utility tool invocations.
Florian Roth (Nextron Systems), Huntrule TeamLinuxprocess_creationMedium132Free2022-03-14Windows Process Creation: Suspicious for/foreach Scan Loop with nslookup or ping
Alerts on Windows command lines using for/foreach loops that also run nslookup or ping, consistent with host scanning.
frack113, Huntrule TeamWindowsprocess_creationMedium113Free2022-03-12Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh215Free2022-03-12Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh327Free2022-03-11Windows process access indicating potential shellcode injection to lsass.exe
Alerts on high-privilege process access from wmiprvse.exe to lsass.exe consistent with potential shellcode injection behavior.
Bhabesh Raj, Huntrule TeamWindowsprocess_accessMedium90Free2022-03-11Windows: Executable Creates Executable via File Creation Events
Flags .exe-to-.exe executable drops on Windows when a running executable creates another .exe, with exclusions for common system/update paths.
frack113, Huntrule TeamWindowsfile_eventLow70Free2022-03-09Windows Process Creation: OfflineScannerShell.exe mpclient.dll DLL Sideloading Risk
Detects OfflineScannerShell.exe launched with an unexpected current directory that could enable mpclient.dll sideloading.
frack113, Huntrule TeamWindowsprocess_creationMedium393Free2022-03-06Windows Process Creation: Replace.exe with -a argument
Detects Replace.exe executions that include the -a argument, which may be used for file replacement.
frack113, Huntrule TeamWindowsprocess_creationMedium265Free2022-03-06Windows Suspicious UltraVNC Command Line With Auto-Reconnect Flags
Alerts on UltraVNC execution using -autoreconnect with -connect and -id in the Windows command line.
Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh151Free2022-03-04PowerShell Base64 Encoded MpPreference Command Lines for Windows Defender Modification
Detects PowerShell Base64 command lines referencing Add-MpPreference/Set-MpPreference to modify Microsoft Defender AV settings.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh147Free2022-03-04Windows Hacktool Execution Flagged by Imphash in Process Creation
Alerts on Windows process executions where the import hash matches known hacktool binaries, even if renamed.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical486Free2022-03-04Windows PowerShell: Disable Microsoft Defender Scanning via Set-MpPreference
Flags PowerShell commands that disable Microsoft Defender scanning/protection settings using Set-MpPreference, including encoded variants.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh308Free2022-03-03Windows: fsutil SymlinkEvaluation behavior modification via command line
Alerts on fsutil commands from cmd/PowerShell that change NTFS SymlinkEvaluation behavior, potentially enabling remote symlink access.
frack113, The DFIR Report, Huntrule TeamWindowsprocess_creationMedium327Free2022-03-02Windows Process Creation: Base64-Obfuscated .NET Reflection Assembly Load Call
Alerts on command lines containing Base64-encoded obfuscation for .NET reflection assembly load calls.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2022-03-01