Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,281 rules
Windows Process Creation: Suspicious GUP.exe Execution from Non-Notepad++ Directories
Alerts on GUP.exe executions from unexpected directories on Windows, excluding known Notepad++ updater paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh168Free2019-02-06Windows Remote Thread Creation via CACTUSTORCH Using Script/Office/Rundll Host Images
Alerts on SysWOW64 remote thread creation initiated by script host or Office binaries consistent with CACTUSTORCH behavior.
"@SBousseaden (detection), Thomas Patzke (rule), Huntrule Team"Windowscreate_remote_threadHigh131Free2019-02-01Chafer malware C2 URLs with /asp.asp?ui= pattern over HTTP proxy
Flags proxy HTTP requests containing the C2 URI pattern /asp.asp?ui= associated with Chafer behavior.
Florian Roth (Nextron Systems), Huntrule Team—proxyHigh127Free2019-01-31Windows netsh.exe Used to Create RDP (3389) Port Forwarding
Flags netsh.exe executions that appear to set up RDP (3389) port forwarding.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationHigh302Free2019-01-29Windows RDP Logon Using Localhost IP Address
Alerts on successful Windows logons (EventID 4624, LogonType 10) originating from localhost IPs.
Thomas Patzke, Huntrule TeamWindowssecurityHigh122Free2019-01-28Windows Registry: New Security Support Provider (SSP) added to LSA configuration
Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.
iwillkeepwatch, Huntrule TeamWindowsregistry_eventHigh122Free2019-01-18Windows Suspicious Child Processes Spawned by Web Server Executables
Alerts when web server processes (e.g., nginx/httpd/caddy/php/tomcat) spawn suspicious Windows command/scripting executables.
Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2019-01-16Windows Process Execution From Uncommon or Sensitive Directories
Alerts on process executions from uncommon/sensitive Windows directories, excluding specific IBM and Citrix updater paths.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh132Free2019-01-16Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix), Huntrule TeamWindowsprocess_creationHigh306Free2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
John Lambert (rule), Huntrule TeamWindowsprocess_creationHigh121Free2019-01-16Windows Process Creation: Suspicious Children Spawned by mshta.exe
Flags mshta.exe spawning command, script, or utility processes commonly abused for executing malicious HTA payloads.
Michael Haag, Huntrule TeamWindowsprocess_creationHigh473Free2019-01-16Windows Cmdkey.EXE Cached Credential Reconnaissance
Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.
jmallette, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2019-01-16Windows userinit.exe Spawns Uncommon Child Processes
Alerts when userinit.exe starts an unexpected child process during logon, suggesting potential persistence via modified logon behavior.
Tom Ueltschi (@c_APT_ure), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh399Free2019-01-12Windows Command Line Logon Script Persistence via UserInitMprLogonScript
Alerts when a Windows process command line references UserInitMprLogonScript, a potential logon-script persistence indicator.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowsprocess_creationHigh173Free2019-01-12Windows Process Creation: Outlook EnableUnsafeClientMailRules Security Setting Enabled
Flags Windows process command lines that reference Outlook’s EnableUnsafeClientMailRules security setting.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2018-12-27