Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
768 rules
Windows: Suspicious child processes spawned by CrushFTP service
Alerts when CrushFTP service (crushftpservice.exe) launches shell/script executables like PowerShell, cmd, mshta, or bash.
Craig Sweeney, Matt Anderson, Jose Oregon, Tim Kasper, Faith Stratton, Samantha Shaw, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium133Free2025-04-10Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh80Free2025-04-09Windows PowerShell History File Access Attempt via ConsoleHost_history.txt
Alerts on Windows process executions whose command line references PowerShell console history files or HistorySavePath.
Luc Génaux, Huntrule TeamWindowsprocess_creationMedium142Free2025-04-03Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Flags PowerShell script blocks that query AD computer delegation-related properties using Get-ADComputer-style discovery.
frack113, Huntrule TeamWindowsps_scriptMedium299Free2025-03-05Windows Scheduled Task Creation via schtasks.exe with curl and PowerShell Command Line Indicators
Alerts on schtasks.exe task creation commands that simultaneously include curl download indicators and PowerShell execution.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium100Free2025-02-05Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh130Free2025-02-05Windows Process Creation: Suspicious cmd.exe Launch with Encoded PowerShell from Cleo Suite
Alerts on cmd.exe launching PowerShell encoded commands from Cleo javaw.exe components with .Download.
Tanner Filip, Austin Worline, Chad Hudson, Matt Anderson, Huntrule TeamWindowsprocess_creationHigh327Free2024-12-09Windows Registry RunMRU PowerShell or WMIC Execution Command Indicators
Alerts on RunMRU registry entries showing PowerShell (encoding/invocation) or WMIC shadowcopy/process call usage.
Ahmed Farouk, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setHigh191Free2024-11-01Windows MeshAgent remote command execution via cmd.exe or PowerShell child processes
Flags cmd.exe or PowerShell spawned by meshagent.exe on Windows, indicating potential remote command execution.
"@Kostastsale, Huntrule Team"Windowsprocess_creationMedium495Free2024-09-22Windows DISM Enables PowerShell Web Access Feature via Command Line
Flags DISM executions that enable the WindowsPowerShellWebAccess feature using /online and /enable-feature parameters.
Michael Haag, Huntrule TeamWindowsprocess_creationHigh102Free2024-09-03Windows PowerShell Web Access Installation via PowerShell Script Block
Detects PowerShell Web Access installation and web authorization configuration from Windows PowerShell script blocks.
Michael Haag, Huntrule TeamWindowsps_scriptHigh307Free2024-09-03Windows Remote Thread Creation in cmd.exe or PowerShell.exe
Alert on remote thread creation where cmd.exe or PowerShell.exe is the initiating process, excluding common system and Defender sources.
Splunk Research Team, Huntrule TeamWindowscreate_remote_threadMedium120Free2024-07-29Windows Process Creation: net.exe or PowerShell creating AD group "ESX Admins"
Alerts on net.exe or PowerShell attempts to create a domain group named "ESX Admins" via AD/command-line parameters.
frack113, Huntrule TeamWindowsprocess_creationHigh122Free2024-07-29PowerShell Launch With --headless From Conhost.exe on Windows
Flags headless ConHost launching PowerShell on Windows based on process name and command-line arguments.
Matt Anderson (Huntress), Huntrule TeamWindowsprocess_creationMedium152Free2024-07-23Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
Nasreddine Bencherchali (Nextron Systems), Nounou Mbeiri, Huntrule TeamWindowsprocess_creationHigh221Free2024-06-26