Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,283 rules
Windows: MMC spawning command-line executables
Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.
Karneades, Swisscom CSIRT, Huntrule TeamWindowsprocess_creationHigh101Free2019-08-05Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.
Nik Seetharaman, Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh342Free2019-07-31Windows Process Creation: Executable Extension Masquerading with .exe After Decoy Extension
Alerts on Windows processes whose paths/command lines use misleading double extensions ending in .exe to cloak executable execution.
Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2019-06-26Windows Security Event 4662 Detects DPAPI Domain Backup Key Extraction from Domain Controllers
Detects read access to LSA secret DPAPI domain backup key objects in Windows Event ID 4662.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh133Free2019-06-20Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh286Free2019-06-15Windows Process Creation: Renamed jusched.exe Execution via Java Scheduler Names
Alerts when Java Update Scheduler descriptions are used to execute a process ending with \jusched.exe on Windows.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh238Free2019-06-04Windows Security 4625 Logon Failures to TargetUserName AAAAAAA Indicative of RDP Scan PoC
Alerts on Windows failed logon (4625) events matching a BlueKeep scanner PoC TargetUserName value.
Florian Roth (Nextron Systems), Adam Bradbury (idea), Huntrule TeamWindowssecurityHigh152Free2019-06-02Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh405Free2019-05-22Potential BearLPE Exploitation via Windows Task Scheduler schtasks.exe DACL Change
Flags schtasks.exe executions with /change, /TN, /RU, and /RP, consistent with task modification tied to BearLPE attempts.
Olaf Hartong, Huntrule TeamWindowsprocess_creationHigh142Free2019-05-22WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
Patryk Prauze - ING Tech, Huntrule TeamWindowsprocess_accessHigh239Free2019-05-20Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
Alec Costello, Huntrule TeamWindowsps_scriptHigh248Free2019-05-16Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.
Markus Neis, Huntrule TeamWindowsnetwork_connectionHigh71Free2019-05-15Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh127Free2019-04-20Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowswmi_eventHigh113Free2019-04-15Linux Command Lines Creating Symlink to /etc/passwd
Alerts on Linux command lines attempting to create symlinks to /etc/passwd via ln -s/ln -f patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High91Free2019-04-05