Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,294 rules
Windows Process Creation: Netcat (ncat/cat) Suspicious Execution
Alerts on Windows process launches of Netcat-like binaries with typical listener/proxy or remote execution command-line flags.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh436Free2021-07-21Windows mshta.exe Process Creation Triggered by Suspicious Command Lines
Alert on mshta.exe launches from suspicious parents and script-like command lines/paths.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-07-17PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh325Free2021-07-16Windows: Suspicious Parent-Serv-U.exe Command-Line Process Spawning
Alerts when Serv-U (\Serv-U.exe) spawns typical command interpreters or execution utilities on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh243Free2021-07-14Windows reg.exe Used to Modify Security Service Start Parameters
Flags reg.exe registry changes that target Start parameters for common security and Windows Defender-related services.
Florian Roth (Nextron Systems), John Lambert (idea), elhoim, Huntrule TeamWindowsprocess_creationHigh459Free2021-07-14Windows PowerShell: AtomicTestHarness Invoke-ATHRemoteFXvGPUDisablementCommand Abuse
Alerts on Windows process command lines invoking AtomicTestHarnesses RemoteFXvGPUDisablement PowerShell execution.
frack113, Huntrule TeamWindowsprocess_creationHigh183Free2021-07-13Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleHigh537Free2021-07-13Windows PowerShell ModuleContents Set to Get-VMRemoteFXPhysicalVideoAdapter
Alerts on PowerShell module creation embedding Get-VMRemoteFXPhysicalVideoAdapter, a potential precursor to RemoteFXvGPUDisablement.exe abuse.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspowershell-classicHigh452Free2021-07-13Windows Uninstall CrowdStrike Falcon Sensor via WindowsSensor.exe /uninstall /quiet
Flags Windows processes uninstalling CrowdStrike Falcon Sensor using WindowsSensor.exe with /uninstall and /quiet.
frack113, Huntrule TeamWindowsprocess_creationHigh203Free2021-07-12Windows Process Injection via Mavinject Using INJECTRUNNING Flag
Alerts on Windows process creation using Mavinject with /INJECTRUNNING, indicative of DLL injection into a running process.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh307Free2021-07-12Windows spoolsv.exe Child Process Execution Indicators
Flags suspicious process executions where spoolsv.exe (print spooler) spawns utility, scripting, or rundll32 children with high integrity.
Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule), Huntrule TeamWindowsprocess_creationHigh201Free2021-07-11Windows Process Creation: MpCmdRun.exe Removing All Windows Defender Definitions
Flags MpCmdRun.exe launched to remove all Windows Defender definition files.
frack113, Huntrule TeamWindowsprocess_creationHigh181Free2021-07-07Windows windefend: Detect Tamper Protection blocks changes to Microsoft Defender settings
Flags Defender tamper protection blocks to disable key Microsoft Defender Antivirus and real-time protection settings.
Bhabesh Raj, Nasreddine Bencherchali, Huntrule TeamWindowswindefendHigh221Free2021-07-05Windows Suspicious DLL Deletion in Spooler Driver Folder (PrintNightmare/CVE-2021-1675)
Alerts when spoolsv.exe deletes a DLL from the Spooler driver folder path on Windows.
Bhabesh Raj, Huntrule TeamWindowsfile_deleteHigh241Free2021-07-01Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Looks for Print Spooler plug-in/module load errors in Windows logs that may indicate CVE-2021-1675 exploitation attempts.
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Tim Shelton, Huntrule TeamWindowsprintservice-adminHigh351Free2021-06-30