Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows PowerShell: Base64 Encoded Reflective .NET Assembly Load
Flags PowerShell command lines containing Base64 fragments consistent with reflective .NET Assembly.Load usage.
Christian Burkard (Nextron Systems), pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh194Free2022-03-01Windows BITS Transfer Jobs Downloading Files with Suspicious Extensions
Flags Windows BITS transfers saving local files with high-risk script/executable extensions while excluding common benign patterns.
frack113, Huntrule TeamWindowsbits-clientMedium152Free2022-03-01Windows BITS Job Creation Triggered by PowerShell
Flags new BITS job creation on Windows when initiated by PowerShell (Event ID 3).
frack113, Huntrule TeamWindowsbits-clientLow111Free2022-03-01Windows BITS job created by bitsadmin.exe (BITS Client EventID 3)
Alerts on new BITS job creation when bitsadmin.exe triggers it (BITS-Client EventID 3).
frack113, Huntrule TeamWindowsbits-clientLow133Free2022-03-01Windows PowerShell CommandLine downloads and executes via WebClient with IEX or DownloadFile
Alerts on PowerShell command lines that use WebClient downloads combined with IEX or DownloadFile, typical of staged payload execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-02-28Windows: Suspicious Process Spawn by Outlook Parent
Alerts on Windows process launches where Outlook.exe spawns known high-risk command execution binaries.
Michael Haag, Florian Roth (Nextron Systems), Markus Neis, Elastic, FPT.EagleEye Team, Huntrule TeamWindowsprocess_creationHigh122Free2022-02-28Windows Registry: Enable Microsoft DDE in Word or Excel Security Settings
Detects registry changes that enable or permit DDE server launch/lookup for Word or Excel.
frack113, Huntrule TeamWindowsregistry_setMedium341Free2022-02-26Suspicious wuauclt.exe Process Creation on Windows with Empty Command-Line Flags
Alert on Windows Update Agent wuauclt.exe launches that have command lines ending with no flags/arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-02-26Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Alerts on processes launched from \Users\Public that execute common scripting/shell binaries or command-line markers.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh282Free2022-02-25Windows: ScreenConnect Client Service Spawning Suspicious Utility Commands
Alerts when ScreenConnect run.cmd leads to child processes like cmd.exe, PowerShell, curl, or other utilities.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @Kostastsale, Huntrule TeamWindowsprocess_creationMedium123Free2022-02-25Windows process creation: CrackMapExec execution via characteristic command-line flags
Alerts on Windows process creation showing CrackMapExec-style command-line flags for local auth and module execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh226Free2022-02-25Windows MSExchangeMailboxReplication .aspx/.asp File Writes Indicating Web Shell Upload
Alerts when MSExchangeMailboxReplication.exe writes .asp or .aspx files on Windows, indicating potentially malicious server-side script drops.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3210Free2022-02-25Windows Process Creation: Hermetic Wiper–style Postgres/PowerShell Command-Line Patterns
Flags Windows process creation with wiper-like PowerShell comsvcs MiniDump and related command-line/paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-02-25Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Flags Windows process creation command-line patterns consistent with BlackByte ransomware techniques.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3110Free2022-02-25Windows Registry: Disable CrashDump via CrashControl DWORD value
Alerts on registry changes that disable Windows crash dumps by writing 0x00000000 to CrashControl.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsregistry_setMedium371Free2022-02-24