Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Creation: wlrmdr.exe with -u Flag or Uncommon Child Process Execution
Flags wlrmdr.exe launched with -u or uncommon children spawned with specific flags, using process creation telemetry.
frack113, manasmbellani, Huntrule TeamWindowsprocess_creationMedium225Free2022-02-16Windows Process Command-Line Dosfuscation Pattern Detection (Potential Obfuscation)
Alerts on Windows command lines containing known dosfuscation-style obfuscation patterns.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium137Free2022-02-15Windows: Rundll32 Executing Registered COM Local Servers via Command-Line { }
Flags rundll32.exe launching COM local servers using -sta/-localserver with braced arguments.
frack113, Huntrule TeamWindowsprocess_creationHigh184Free2022-02-13Windows Process Creation: ScreenConnect Service Execution
Alerts on Windows executions identified as ScreenConnect service/product/company strings, indicating potential remote access C2 activity.
frack113, Huntrule TeamWindowsprocess_creationMedium257Free2022-02-13Windows: Process creation matching GoTo Opener (LogMeIn) for remote access tooling
Alerts on Windows process execution identified as “GoTo Opener” by LogMeIn, which may indicate remote access tool use.
frack113, Huntrule TeamWindowsprocess_creationMedium361Free2022-02-13Windows: reg.exe Adds Windows Defender Exclusion Paths via Registry Value Update
Detects reg.exe commands that modify Windows Defender/Microsoft Antimalware exclusion path registry entries.
frack113, Huntrule TeamWindowsprocess_creationMedium455Free2022-02-13Windows esentutl.exe Browser Data Collection via -r and WebCache path
Flags esentutl.exe runs with -r and WebCache references, indicating potential browser data collection.
frack113, Huntrule TeamWindowsprocess_creationMedium91Free2022-02-13Windows File Creation of ScreenConnect Temporary Installation Artefact
Flags Windows file events referencing temporary ScreenConnect artefacts under the \Bin\ScreenConnect.* path.
frack113, Huntrule TeamWindowsfile_eventMedium143Free2022-02-13GoToAssist Temporary File Drop in Windows Temp Directory
Flags creation of GoToAssist Remote Support Expert temp installation artefacts under Windows AppData\Temp.
frack113, Huntrule TeamWindowsfile_eventMedium444Free2022-02-13Windows schtasks Creates Registry-Backed Base64 PowerShell Payload via Encoded Command
Flags schtasks.exe scheduling that triggers PowerShell to decode a base64 payload pulled from Windows Registry.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-02-12Windows reg.exe Used to Modify RDP Terminal Server Registry Values
Flags reg.exe command lines that modify Terminal Server registry values controlling RDP enablement and behavior.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh2710Free2022-02-12PowerShell DirectorySearcher AD Computer Enumeration via System.DirectoryServices.DirectorySearcher
Flags PowerShell DirectorySearcher queries that load directory properties and enumerate results from Active Directory.
frack113, Huntrule TeamWindowsps_scriptMedium151Free2022-02-12Windows Process Execution: ZeroLogon PoC Tool (cool.exe/zero.exe) via cmd.exe
Alerts on cmd.exe launching cool.exe/zero.exe with ZeroLogon PoC-style arguments and follow-on taskkill or PowerShell activity.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh193Free2022-02-12Windows process creation: flag suspicious program names and PowerShell script indicators
Alerts on suspicious Windows process image names and PowerShell command-line script/tool patterns commonly used in malicious tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-02-11Windows LogMeIn LMIGuardianSvc Execution Associated with Remote Access Tools
Flags Windows process launches identified as LogMeIn LMIGuardianSvc by Description/Product/Company attributes.
frack113, Huntrule TeamWindowsprocess_creationMedium345Free2022-02-11