Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,290 rules
Windows Process Masquerading: msdtc.exe and gpsvc.exe launched from Non-System Paths
Alerts on msdtc.exe or gpsvc.exe launched from paths outside Windows System32/SysWOW64.
Trent Liffick (@tliffick), Bartlomiej Czyz (@bczyz1), Huntrule TeamWindowsprocess_creationHigh1710Free2020-06-03Windows: Renamed Sysinternals DebugView Process Execution
Flags Windows executions labeled as Sysinternals DebugView when the image is not the original Dbgview.exe.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh124Free2020-05-28ComRAT Proxy HTTP Requesting index.php with h Parameter
Flags proxy HTTP requests with URIs containing /index/index.php?h=, consistent with web-based C2 behavior.
Florian Roth (Nextron Systems), Huntrule Team—proxyHigh72Free2020-05-26Windows netsh.exe Whitelists Allowed Program from Suspicious Path in Firewall
Flags netsh.exe firewall allow rules that whitelist a program located in suspicious Windows filesystem paths.
Sander Wiebing, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh435Free2020-05-25Windows RDP Port 3389 Allowed via netsh.exe Firewall Rule Creation
Flags netsh.exe commands that add firewall rules allowing TCP port 3389 (RDP).
Sander Wiebing, Huntrule TeamWindowsprocess_creationHigh364Free2020-05-23Windows Registry: Office VBAWarning Disabled (VBAWarnings set to 1)
Alerts on Security\VBAWarnings being set to DWORD 0x00000001, enabling all Office VBA macros.
Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh92Free2020-05-22Windows Registry Set AccessVBOM DWORD=1 Disables Access Security for Access VBA
Alerts on Windows registry changes setting Security\AccessVBOM to DWORD 1, disabling VBA trust access to bypass Office warnings.
Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh375Free2020-05-22Windows: CrackMapExec PowerShell obfuscation via join/split static patterns
Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.
Thomas Patzke, Huntrule TeamWindowsprocess_creationHigh81Free2020-05-22Windows Network Connections Initiated by Notepad.exe
Alerts when notepad.exe initiates an outbound network connection, excluding typical printing traffic on port 9100.
EagleEye Team, Huntrule TeamWindowsnetwork_connectionHigh196Free2020-05-14Windows Registry Set: ServiceDll Path Ending with \CurrentControlSet\Services\wercplsupport\Parameters\ServiceDll
Alerts on Windows registry writes to a specific Services\wercplsupport\Parameters\ServiceDll target path.
Trent Liffick (@tliffick), Huntrule TeamWindowsregistry_setHigh72Free2020-05-14Windows Persistence Attempt via sc config or wmic COR_PROFILER (Blue Mockingbird)
Flags sc.exe sc config and wmic.exe COR_PROFILER command lines tied to wercplsupporte.dll references.
Trent Liffick (@tliffick), Huntrule TeamWindowsprocess_creationHigh111Free2020-05-14Windows Registry Ports Key Changes with Script/Binary File Indicators
Flags registry modifications to the Ports key with path- or executable/script-like details that may indicate printer-based exploitation attempts.
EagleEye Team, Florian Roth (Nextron Systems), NVISO, Huntrule TeamWindowsregistry_setHigh82Free2020-05-13Windows Process Creation: Add-PrinterPort Commands with Suspicious File Paths
Flags suspicious Add-PrinterPort usage referencing .exe/.dll/.bat or “Generic / Text Only” in Windows process command lines.
EagleEye Team, Florian Roth, Huntrule TeamWindowsprocess_creationHigh107Free2020-05-13Windows: Detect rar.exe Archive Creation Using Password or Compression Options
Alerts on rar.exe command lines that include both password protection (-hp) and additional compression/archive flags.
"@ROxPinTeddy, Huntrule Team"Windowsprocess_creationHigh308Free2020-05-12Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
NVISO, Huntrule TeamWindowsfile_eventHigh82Free2020-05-11