Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,301 rules
Windows schtasks Creates Registry-Backed Base64 PowerShell Payload via Encoded Command
Flags schtasks.exe scheduling that triggers PowerShell to decode a base64 payload pulled from Windows Registry.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-02-12Windows reg.exe Used to Modify RDP Terminal Server Registry Values
Flags reg.exe command lines that modify Terminal Server registry values controlling RDP enablement and behavior.
pH-T (Nextron Systems), @Kostastsale, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh2710Free2022-02-12Windows Process Execution: ZeroLogon PoC Tool (cool.exe/zero.exe) via cmd.exe
Alerts on cmd.exe launching cool.exe/zero.exe with ZeroLogon PoC-style arguments and follow-on taskkill or PowerShell activity.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationHigh193Free2022-02-12Windows process creation: flag suspicious program names and PowerShell script indicators
Alerts on suspicious Windows process image names and PowerShell command-line script/tool patterns commonly used in malicious tooling.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh102Free2022-02-11Windows File Creation Indicators for Local SAM Database Exports
Alerts on Windows file creations with filenames indicative of a local SAM export or backup artifact.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh198Free2022-02-11Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Alerts on command lines using TrolleyExpress.exe PID parameters consistent with LSASS memory dumping on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-02-10Windows LSASS memory access from TrolleyExpress/ProcessDump/dump64 processes
Alerts on Windows processes attempting to access lsass.exe from TrolleyExpress.exe, ProcessDump.exe, or dump64.exe with dump-like access rights.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh141Free2022-02-10Windows LSASS Memory Access Triggered by Source Image Containing 'dump' Keyword
Alerts when a process named with 'dump' requests specific access rights to lsass.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh70Free2022-02-10Windows Script Interpreter Execution From Suspicious Folders via Command-Line Flags
Flags-and-location-based detection of cscript/wscript/mshta-style script execution launched from TEMP/Public/user directories.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh338Free2022-02-08Windows Process Command Line Network Recon via nslookup LDAP SRV Query
Identifies Windows command lines running nslookup with an LDAP SRV domain controller discovery query string.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2022-02-07Windows Process Creation: Scheduled Task Creation via schtasks and wscript/vbscript
Alerts on Windows command lines that combine schtasks task creation with wscript running VBScript for persistence.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationHigh91Free2022-02-07Windows: whoami.exe Executed by Privileged Accounts
Flags execution of whoami.exe from privileged-like accounts using Windows process creation events.
Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Huntrule TeamWindowsprocess_creationHigh154Free2022-01-28Windows: Detect XORDump Utility Launch With LSASS Dump and Debug Module Switches
Alerts on xordump.exe spawning with LSASS-targeting and dump-module switches indicative of credential theft.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3210Free2022-01-28Linux auth logs: pkexec and XAUTHORITY strings indicating PwnKit (CVE-2021-4034) attempt
Alerts on Linux auth log entries with pkexec and PwnKit-related environment/session keywords consistent with CVE-2021-4034 attempts.
Sreeman, Huntrule TeamLinuxauthHigh93Free2022-01-26Windows: RunXCmd Command-Line Execution with System or TrustedInstaller Accounts
Flags RunXCmd usage on Windows when invoked to execute commands as System or TrustedInstaller.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh172Free2022-01-24