Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,302 rules
Windows Process Creation: Base64-Obfuscated .NET Reflection Assembly Load Call
Alerts on command lines containing Base64-encoded obfuscation for .NET reflection assembly load calls.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh71Free2022-03-01Windows PowerShell: Base64 Encoded Reflective .NET Assembly Load
Flags PowerShell command lines containing Base64 fragments consistent with reflective .NET Assembly.Load usage.
Christian Burkard (Nextron Systems), pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh194Free2022-03-01Windows PowerShell CommandLine downloads and executes via WebClient with IEX or DownloadFile
Alerts on PowerShell command lines that use WebClient downloads combined with IEX or DownloadFile, typical of staged payload execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-02-28Windows: Suspicious Process Spawn by Outlook Parent
Alerts on Windows process launches where Outlook.exe spawns known high-risk command execution binaries.
Michael Haag, Florian Roth (Nextron Systems), Markus Neis, Elastic, FPT.EagleEye Team, Huntrule TeamWindowsprocess_creationHigh122Free2022-02-28Suspicious wuauclt.exe Process Creation on Windows with Empty Command-Line Flags
Alert on Windows Update Agent wuauclt.exe launches that have command lines ending with no flags/arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-02-26Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Alerts on processes launched from \Users\Public that execute common scripting/shell binaries or command-line markers.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh302Free2022-02-25Windows process creation: CrackMapExec execution via characteristic command-line flags
Alerts on Windows process creation showing CrackMapExec-style command-line flags for local auth and module execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh226Free2022-02-25Windows MSExchangeMailboxReplication .aspx/.asp File Writes Indicating Web Shell Upload
Alerts when MSExchangeMailboxReplication.exe writes .asp or .aspx files on Windows, indicating potentially malicious server-side script drops.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3210Free2022-02-25Windows Process Creation: Hermetic Wiper–style Postgres/PowerShell Command-Line Patterns
Flags Windows process creation with wiper-like PowerShell comsvcs MiniDump and related command-line/paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-02-25Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Flags Windows process creation command-line patterns consistent with BlackByte ransomware techniques.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3410Free2022-02-25Windows Scheduled Task Creation via schtasks with Suspicious Command-Line Patterns
Flags schtasks.exe /Create commands containing suspicious interpreter, encoding, hidden execution, or unusual path/script components.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh432Free2022-02-23Windows explorer.exe spawned with /NOUACCHECK flag for UAC bypass behavior
Alerts on explorer.exe executions that include /NOUACCHECK, indicating potential bypass of UAC checks for child processes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-02-23Windows Process Execution of Tor or Tor Browser (tor.exe / Firefox-based)
Flags Windows execution of tor.exe or Tor Browser’s bundled Firefox from the expected installation path.
frack113, Huntrule TeamWindowsprocess_creationHigh112Free2022-02-20Windows Sysmon DNS Query to .onion or Tor Gateway Domains
Alerts when Windows Sysmon DNS queries target .onion or Tor gateway/proxy-related domain suffixes.
frack113, Huntrule TeamWindowsdns_queryHigh377Free2022-02-20Windows DNS Client Query for .onion and Tor-related Domains
Alerts on Windows DNS queries resolving .onion and related Tor/hidden-service domains.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsdns-clientHigh93Free2022-02-20