Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,298 rules
Windows: Alert on Java.exe Spawning Suspicious System and Script Binaries
Triggers when java.exe launches a child utility commonly abused for command execution and administration.
Andreas Hunkeler (@Karneades), Florian Roth, Huntrule TeamWindowsprocess_creationHigh70Free2021-12-17Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
frack113, Huntrule TeamWindowsprocess_creationHigh403Free2021-12-16Windows wbadmin.exe Deletes All Backup Copies (keepVersions:0)
Flags wbadmin.exe executions that delete all backups/system state backups using keepVersions:0.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-12-13Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
frack113, Huntrule TeamWindowsprocess_creationHigh245Free2021-12-13Webserver JNDI-Exploit-Kit Exploitation Indicators via Known Payload Paths
Flags webserver requests whose URL paths match known JNDI-Exploit-Kit exploit, deserialization, and memshell pattern strings.
Florian Roth (Nextron Systems), Huntrule TeamWebwebserverHigh162Free2021-12-12Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Alerts when SharpView.exe runs with command-line indicators of AD and network discovery/enumeration activity.
frack113, Huntrule TeamWindowsprocess_creationHigh192Free2021-12-10Webserver log detection of Log4j CVE-2021-44228 JNDI payloads in User-Agent, URI query, or Referer
Flags webserver requests with ${jndi:...} payloads in User-Agent, URI query, or Referer indicative of Log4Shell attempts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh285Free2021-12-10Webserver detection of Log4j RCE (CVE-2021-44228) JNDI injection patterns
Detects webserver traffic containing Log4Shell-style JNDI injection payload strings, excluding Nessus scan artifacts.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh111Free2021-12-10Windows Process Creation: Executable Image Missing Absolute Path (Possible Process Ghosting)
Flags Windows process creation where the executable Image lacks an absolute path, potentially indicating process ghosting.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh321Free2021-12-09Windows: Suspicious PowerShell Interactive History Files Created as SYSTEM
Alerts on creation of PowerShell interactive history/profile files under SYSTEM, signaling privileged PowerShell activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh114Free2021-12-07Windows: User Added to Local Remote Desktop Users Group via Net or PowerShell
Detects Windows command-line activity that adds a user to the local Remote Desktop Users group using net localgroup or Add-LocalGroupMember.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh302Free2021-12-06Windows Process Command Line Containing Whoami as First Parameter
Flags Windows process creations with command lines containing '.exe whoami' to surface potential discovery behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-11-29Windows Regsvr32.exe Executed with Suspicious File Extension Masquerading as DLL
Alerts when REGSVR32.exe runs with a command-line argument ending in a suspicious masquerade file extension.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh151Free2021-11-29Windows File Writes from NPPSpy Hacktool: NPPSpy.txt and NPPSpy.dll
Alerts on Windows file events writing NPPSpy.txt or NPPSpy.dll, consistent with credential dumping by the NPPSpy hacktool.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh102Free2021-11-29Windows Process Creation: Dump64.EXE Renamed into Visual Studio Folder
Alerts on Visual Studio–staged dump64.exe masquerading, potentially indicating an attempt to bypass Windows Defender AV.
Austin Songer @austinsonger, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2021-11-26