Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,304 rules
Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Alerts on rundll32 launching the Windows Key Manager (keymgr / KRShowKeyMgr), a potential credential access step.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-04-21Windows process contacting Dropbox API from non-Dropbox executables
Alerts when a non-Dropbox executable makes initiated connections to Dropbox API endpoints on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh91Free2022-04-20Windows Process Execution via 7zFM.exe Indicative of CVE-2022-29072 Exploitation
Alerts when 7zFM.exe spawns cmd.exe or PowerShell with command-line patterns consistent with CVE-2022-29072 exploitation attempts.
frack113, @kostastsale, Huntrule TeamWindowsprocess_creationHigh383Free2022-04-17Windows schtasks.exe scheduled task creation from suspicious folders
Alerts on schtasks.exe /create using PowerShell/cmd and suspicious folder paths like ProgramData.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh404Free2022-04-15Windows Network Connections Initiated by Eqnedt32.EXE
Identifies outbound network connections started by eqnedt32.exe on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh132Free2022-04-14Windows RPCSS svchost (-k RPCSS) Process Spawn Anomaly (Potential CVE-2022-26809)
Alerts on svchost.exe running RPCSS spawning anomalous child processes indicative of potential RPC abuse.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-04-13Windows File Creation: PowerShell webAdministration Module Path Used in CVE-2022-24527 LPE
Flags Windows file events creating webAdministration.psm1 under PowerShell modules, consistent with CVE-2022-24527 LPE behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh214Free2022-04-13Windows Process Creation: SQLite Access to Firefox Profile Databases
Alerts when Windows runs SQLite tooling to query Firefox profile DBs like cookies.sqlite or places.sqlite.
frack113, Huntrule TeamWindowsprocess_creationHigh92Free2022-04-08Windows Task Scheduler persistence using svchost-launched PowerShell with hidden/Bypass flags
Alerts on svchost.exe Schedule tasks spawning PowerShell with hidden window and execution policy bypass flags.
pH-T (Nextron Systems), Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-04-08Windows PowerShell execution from C:\Users\Public
Flags PowerShell command lines that reference C:\Users\Public, indicating likely script execution from a common public staging area.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2022-04-06Windows: Detect Suspicious DumpMinitool.exe Execution via Process Command-Line
Alerts on suspicious command-line usage of DumpMinitool.exe on Windows, leveraging process creation Image, OriginalFileName, and command-line text.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-04-06Windows Registry Key Change Disabling System Restore
Detects registry writes that disable Windows System Restore via policy/config keys set to DWORD 0x00000001.
frack113, Huntrule TeamWindowsregistry_setHigh211Free2022-04-04Windows Registry Service Persistence via SafeBoot Control Keys
Flags Windows registry writes that configure a service to load in Safe Mode (SafeBoot Minimal/Network).
frack113, Huntrule TeamWindowsregistry_setHigh92Free2022-04-04Windows Registry Key Changes Disabling PowerShell Logging for Current User
Detects registry changes that disable PowerShell module/script logging and transcription by setting logging keys to DWORD 0.
frack113, Huntrule TeamWindowsregistry_setHigh448Free2022-04-02Windows PowerShell IEX Invocation Patterns in Process Creation Command Lines
Alerts on suspicious PowerShell command lines that pipe or otherwise invoke IEX and may include Base64 decoding.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh161Free2022-03-24