Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,295 rules
Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.
Vadim Khrykov, Cyb3rEng, Huntrule TeamWindowsprocess_creationHigh162Free2021-08-23Windows UAC bypass using wsreset.exe with high/SYSTEM integrity
Alerts when wsreset.exe is executed with elevated integrity (High or SYSTEM), indicating a potential UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2021-08-23Windows Process UAC Bypass via Windows Media Player osksupport.dll (osk.exe → cmd.exe)
Alerts on osk.exe spawning cmd.exe under mmc event viewer with high/system integrity, consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh315Free2021-08-23Windows UAC Bypass via pkgmgr.exe Launching dism.exe (High/System Integrity)
Detects pkgmgr.exe spawning dism.exe with High/System integrity levels on Windows, a pattern used in UAC bypass attempts.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh418Free2021-08-23Windows UAC Bypass via consent.exe and werfault.exe with comctl32.dll-related behavior
Alerts on consent.exe parent launching werfault.exe with high/system integrity levels, consistent with potential UAC bypass attempts.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh295Free2021-08-23Windows UAC bypass via changepk.exe launched from slui.exe with elevated integrity
Flags changepk.exe execution from slui.exe with High/System integrity to identify potential UAC bypass behavior on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2021-08-23Windows Process Creation: Suspicious splwow64.exe Missing Command-Line Parameters
Flags Windows executions of splwow64.exe where the command line ends at the executable with no parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2021-08-23Windows UAC Bypass via WoW64 Logger DLL Hijack (Process Access Pattern)
Flags SysWOW64 process-access behavior with high granted access and unknown call traces consistent with a WoW64 logger DLL hijack UAC bypass.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh112Free2021-08-23Windows Named Pipe Creation Matching EfsPotato-Style \\pipe\\srvsvc
Alerts on Windows named pipe creation events matching an EfsPotato-style PipeName pattern (\pipe\ and \pipe\srvsvc), excluding common benign contexts.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdHigh151Free2021-08-23UAC Bypass via Windows Media Player: DllHost.exe spawning osk.exe writing OskSupport.dll to Temp
Flags file events where Temp\OskSupport.dll is targeted alongside DllHost.exe and Windows Media Player\osk.exe, consistent with a UAC bypass attempt.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh82Free2021-08-23Windows UAC Bypass via consent.exe with comctl32.dll file path pattern
Detects suspicious target path patterns involving consent.exe.@ and comctl32.dll consistent with UAC bypass staging.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsfile_eventHigh163Free2021-08-23Windows Office Applications Creating Executable/Script Files with Suspicious Extensions
Flags Office application processes creating .exe/.dll/.ps1 and other script or executable files on Windows.
Vadim Khrykov (ThreatIntel), Cyb3rEng (Rule), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh367Free2021-08-23Windows: Suspicious explorer.exe Child Process Spawned by RazerInstaller.exe
Flags explorer.exe spawned by RazerInstaller.exe when the installer runs at System/high integrity.
Florian Roth (Nextron Systems), Maxime Thiebaut, Huntrule TeamWindowsprocess_creationHigh153Free2021-08-23PowerShell Write-Hijack HackTool Creates .bat for DLL Hijack Execution (Windows)
Flags PowerShell creating .bat files consistent with PowerUp Write-Hijack DLL abuse on Windows.
Subhash Popuri (@pbssubhash), Huntrule TeamWindowsfile_eventHigh101Free2021-08-21Antivirus alerts on known hacktool and attack tool signatures
Alerts on Antivirus detections matching hacktool signature prefixes or offensive tool names for investigation.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusHigh133Free2021-08-16