Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,317 rules
Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
Nasreddine Bencherchali (Nextron Systems), frack113 , X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-01Windows Process Creation: Suspicious ShellExec_RunDLL Command-Line Usage
Detects Windows command lines containing ShellExec_RunDLL along with other suspicious execution indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-09-01Windows net.exe Commands Manipulating Built-in Default Accounts (administrator/guest)
Flags net.exe/net1.exe process creation when command lines reference built-in Administrator/guest/default accounts with suspicious active/disable context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh284Free2022-09-01Windows Suspicious cmd.exe Launch After net use Mounting WebDAV Share
Flags cmd.exe command lines that mount an Internet WebDAV share with net use and immediately execute content from DavWWWRoot.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2022-09-01Windows Process Creation: DefenderCheck.exe Execution (PUA/Signature Evasion)
Alerts on execution of DefenderCheck.exe/description to identify potential AV signature probing and evasion preparation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh431Free2022-08-30Windows Network Connection from Cmstp.EXE (Outbound)
Alerts on outbound network connections initiated by cmstp.exe, which is uncommon and may indicate process misuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh60Free2022-08-30Windows: cmstp.exe Loading DLL/OCX from Suspicious Paths
Alerts when cmstp.exe loads DLL/OCX from suspicious directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh82Free2022-08-30Windows RTCore64 Service Installation via Service Control Manager (Event ID 7045)
Alerts on creation of the RTCore64 Windows service via Service Control Manager Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh101Free2022-08-30Windows SharpLdapWhoami Execution via LDAP Whoami Methods
Flags execution of SharpLdapWhoami on Windows using LDAP-related whoami alternative method parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh178Free2022-08-29Windows Process Creation: nimgrab.exe Execution (Nim Tool Download Behavior)
Alerts on execution of nimgrab.exe on Windows when hashes match known indicators.
frack113, Huntrule TeamWindowsprocess_creationHigh163Free2022-08-28Windows Network Connections by wscript/cscript Script Interpreters to Non-Local IPs
Flags wscript.exe/cscript.exe making outbound connections to non-local destination IPs.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh141Free2022-08-28Windows Scheduled Task Index Registry Tampering Hiding Tasks from Query Tools
Alerts on registry set events that tamper scheduled task TaskCache Tree "Index" DWORD to 0.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh123Free2022-08-26Windows Process Execution: Suspicious PowerShell Encoded Command with Exec Bypass
Flags Windows process creations with a bypass-and-encoded PowerShell Start-Job command-line pattern linked to Mercury-related activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh324Free2022-08-26Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh264Free2022-08-25Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh60Free2022-08-24