Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,288 rules
Windows Process Access to svchost.exe with High-Rights GrantedAccess
Alerts on high-privilege access to svchost.exe when process call context is UNKNOWN, excluding MSBuild-origin traffic.
Tim Burrell, Huntrule TeamWindowsprocess_accessHigh157Free2020-01-02Windows Process Creation: svchost.exe Spawned Without Command-Line Arguments
Flags svchost.exe process starts lacking command-line values, excluding rpcnet/rpcnetp parent cases.
David Burkett, @signalblur, Huntrule TeamWindowsprocess_creationHigh111Free2019-12-28Windows CreateMiniDump.exe HackTool Execution via Process Creation
Detects the execution of CreateMiniDump.exe using image name and a specific IMPHASH.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2019-12-22Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Alerts on SharpHound/Bloodhound-like processes launching with discovery-focused command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh174Free2019-12-20Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)
Detects Windows Security Event 4799 where checkadmin.exe targets “Administr*” accounts, consistent with admin account enumeration.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowssecurityHigh406Free2019-12-20Ursnif dropper download URLs matching PHP l= parameter ending in CAB
Flags proxy responses where a request URI contains /.php?l= and ends with .cab, returning HTTP 200.
Thomas Patzke, Huntrule Team—proxyHigh3110Free2019-12-19Windows Process Execution Indicative of Ryuk-Style Ransomware Behavior
Flags suspicious Windows process command lines combining autorun persistence, public staging, file backup wiping, and service stoppage behavior.
Florian Roth (Nextron Systems), Vasiliy Burov, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh373Free2019-12-16Proxy access to raw paste endpoints on paste.ee and Pastebin-style services
Alerts on proxy requests for raw paste service URLs that can be used to stage or fetch malicious payloads.
Florian Roth (Nextron Systems), Huntrule TeamWebproxyHigh131Free2019-12-05Windows ProcDump Execution via Renamed Binary
Flags renamed ProcDump usage on Windows by matching procdump indicators and dump flags while excluding known executable names.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2019-11-18Windows Security: Anonymous Logon (4624 LogonType 3) with Loopback IPs
Alerts on Windows 4624 LogonType 3 with ANONYMOUS LOGON and loopback IPs, matching RottenPotato-like patterns.
"@SBousseaden, Florian Roth, Huntrule Team"WindowssecurityHigh111Free2019-11-15Windows Process Creation: Suspicious SetupComplete.cmd execution for CVE-2019-1378 exploitation
Alerts on cmd.exe parent command lines executing SetupComplete.cmd or PartnerSetupComplete.cmd from Windows Setup script paths.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh187Free2019-11-15Windows msiexec.exe Execution from Uncommon Directory
Alerts when msiexec.exe starts from a non-standard path, which may indicate masquerading.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3410Free2019-11-14Suspicious APT User-Agent Strings in Proxy Logs
Alerts when proxy requests contain known APT-style user agent strings indicating likely malicious client behavior.
Florian Roth (Nextron Systems), Markus Neis, Huntrule TeamWebproxyHigh152Free2019-11-12Proxy User-Agent Matching APT40 Dropbox Tool on api.dropbox.com
Alerts on proxy requests using a fixed Chrome 36 user-agent to api.dropbox.com.
Thomas Patzke, Huntrule Team—proxyHigh132Free2019-11-12Windows: Command-line contains long ab-prefixed string seen in TropicTrooper activity (Nov 2018)
Detects Windows processes whose command line contains a known TropicTrooper campaign indicator string.
"@41thexplorer, Microsoft Defender ATP, Huntrule Team"Windowsprocess_creationHigh168Free2019-11-12