Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,305 rules
Windows PowerShell Base64 Encoded Commands Containing Invoke- ( -e )
Flags PowerShell executions using the -e encoded command flag with Base64 patterns consistent with an Invoke- call.
pH-T (Nextron Systems), Harjot Singh, @cyb3rjy0t, Huntrule TeamWindowsprocess_creationHigh131Free2022-05-20Windows grpconv Utility Execution with Output Option
Alerts on Windows process command lines invoking GrpConv with -o, potentially for .grp conversion or persistence.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-05-19Windows Office Applications Downloading Files via HTTP/HTTPS
Detects Office binaries invoked with command lines containing http/https, indicating potential arbitrary file download.
Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationHigh71Free2022-05-17Windows Event Log Cleared (EventID 104, Microsoft-Windows-Eventlog)
Alerts when Microsoft-Windows-Eventlog reports Event ID 104 for core event log channels, indicating log clearing.
Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh376Free2022-05-17Windows IEExec.EXE Download-and-Execute via Process Creation
Flags IEExec.exe executions that reference HTTP/HTTPS URLs for download-and-execute behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh346Free2022-05-16Windows Remote Thread Creation via Ttdinject.exe Proxy
Alerts on Windows create-remote-thread events initiated by Ttdinject.exe used as a proxy.
frack113, Huntrule TeamWindowscreate_remote_threadHigh122Free2022-05-16Windows Service Creation for KrbRelayUp (KrbSCM)
Flags creation of the KrbSCM Windows service, a known KrbRelayUp installation artifact.
Sittikorn S, Tim Shelton, Huntrule TeamWindowssystemHigh3410Free2022-05-11Windows PowerShell Execution of Obfuscated One-Liner for In-Memory Module Download
Alerts on Windows PowerShell one-liners containing an obfuscated in-memory download/execute pattern from an HTTP URL.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh132Free2022-05-09Windows Security Event 5379: Opened Password-Protected ZIP from Outlook Attachment
Flags Windows events where a password-protected ZIP is opened from Outlook Temporary Internet Files.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh152Free2022-05-09Windows Security: Password-Protected ZIP Opened with Suspicious Filename Indicators
Alerts when Windows opens password-protected ZIP contents with filenames commonly tied to invoices, orders, payments, and deliveries.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh217Free2022-05-09Windows Process Creation: Cobalt Strike module/command strings entered in cmd.exe
Alerts when cmd.exe command lines include Cobalt Strike module/command strings.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh434Free2022-05-06Windows Process Command Line: Accidental Cobalt Strike Commands in cmd.exe
Flags cmd.exe executions whose command lines include known Cobalt Strike command terms.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh60Free2022-05-06Windows Raspberry Robin Execution via cmd.exe Parent and External-File Payload
Flags cmd.exe with /r from external media launching msiexec.exe /q that includes an HTTP/HTTPS payload URL.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh1810Free2022-05-06Windows: Raspberry Robin Command Execution via fodhelper.exe and rundll32/regsvr32
Flags Windows process-spawn chains where fodhelper.exe runs rundll32/regsvr32 with Raspberry Robin-style command-line patterns.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh388Free2022-05-06Windows Process Creation: Suspicious Child Processes Spawned by regsvr32.exe
Alerts when regsvr32.exe spawns suspicious child processes like PowerShell, mshta, or scripting utilities.
elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-05-05