Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
29 rules
Windows SimpleService Execution via Remote Access Tool Wrapper Paths
Flags Windows processes running SimpleService.exe from remote access tool wrapper directories.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium172Free2024-02-23Windows Network Connections to *.devtunnels.ms
Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.
Kamran Saifullah, Huntrule TeamWindowsnetwork_connectionMedium101Free2023-11-20Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Flags Windows service installation or updates for remote access tool services using Service Control Manager events.
Connor Martin, Nasreddine Bencherchali, Huntrule TeamWindowssystemMedium448Free2022-12-23Windows Security Event 4697 Service Install of Remote Access Tools
Alerts on Windows service creation (EID 4697) where the service name matches known remote access tool indicators.
Connor Martin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssecurityMedium123Free2022-12-23Windows RDP Registry Settings Modified to Zero
Alerts when RDP-related registry values are set to 0, potentially weakening remote access controls.
Samir Bousseaden, David ANDRE, Roberto Rodriguez @Cyb3rWard0g, Nasreddine Bencherchali, Huntrule TeamWindowsregistry_setMedium193Free2022-09-29Windows DNS Queries to Remote Support and Remote Access Domains From Non-Browser Processes
Alert on DNS lookups for remote access service domains from non-browser executables, including RustDesk subdomains.
frack113, Connor Martin, Huntrule TeamWindowsdns_queryMedium112Free2022-07-11Windows AnyDesk Executed from Suspicious Directory
Alerts on AnyDesk execution from non-standard folders on Windows, indicating potential remote access abuse.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh328Free2022-05-20Windows Process Creation: ScreenConnect Service Execution
Alerts on Windows executions identified as ScreenConnect service/product/company strings, indicating potential remote access C2 activity.
frack113, Huntrule TeamWindowsprocess_creationMedium267Free2022-02-13Windows: Process creation matching GoTo Opener (LogMeIn) for remote access tooling
Alerts on Windows process execution identified as “GoTo Opener” by LogMeIn, which may indicate remote access tool use.
frack113, Huntrule TeamWindowsprocess_creationMedium371Free2022-02-13Windows LogMeIn LMIGuardianSvc Execution Associated with Remote Access Tools
Flags Windows process launches identified as LogMeIn LMIGuardianSvc by Description/Product/Company attributes.
frack113, Huntrule TeamWindowsprocess_creationMedium355Free2022-02-11Windows HackTool Activity: Evil-WinRM Ruby Process with -i, -u, -p Arguments
Flags Ruby processes launched with Evil-WinRM parameters (-i, -u, -p), indicative of WinRM remote access attempts.
frack113, Huntrule TeamWindowsprocess_creationMedium2810Free2022-01-07Windows PowerShell script enabling WinRM via Enable-PSRemoting
Alerts on PowerShell scripts that include Enable-PSRemoting, a common step to activate WinRM for remote access.
frack113, Huntrule TeamWindowsps_scriptMedium91Free2022-01-07Windows ScreenConnect Installation Execution via Remote Access Parameters
Flags Windows executions of ScreenConnect with remote access command-line parameters indicating remote session setup.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium113Free2021-02-11WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
Patryk Prauze - ING Tech, Huntrule TeamWindowsprocess_accessHigh239Free2019-05-20