Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,280 rules
Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Flags PowerShell script blocks containing Base64 strings matching known shellcode markers.
David Ledbetter (shellcode), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh113Free2018-11-17Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2018-10-30Antivirus Web Shell Signature Matches Across ASP, JSP, PHP, Perl, and VBS
Alerts on AV signatures indicating web shells/backdoors (ASP/JSP/PHP/Perl/VBS/Webshell) to support fast investigation of persistence.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusHigh248Free2018-09-09Antivirus alerts for suspicious file paths and web/script file extensions
Alerts on AV hits involving suspicious file locations and web/script-related extensions.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusHigh112Free2018-09-09Windows PowerShell Suspicious Encoded Command-Line Execution
Alerts on PowerShell launched with encoded-command switches and embedded encoded content patterns in the command line.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, Anton Kutepov, oscd.community, Huntrule TeamWindowsprocess_creationHigh238Free2018-09-03Windows Process in Suspicious Folder Initiating Network Connections to File Sharing Domains
Alerts on outbound connections to file sharing domains from Windows executables running out of suspicious temp/recycle/task paths.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh423Free2018-08-30Windows LSASS process access blocked by Attack Surface Reduction (Windows Defender event 1121)
Alerts on windefend EventID 1121 for blocked access to lsass.exe, excluding common benign process callers.
Markus Neis, Huntrule TeamWindowswindefendHigh171Free2018-08-26Windows Registry Run Key Set to Executable in Suspicious Folder
Flags new Windows Run key values pointing to executables in suspicious folders, excluding known update/Spotify patterns.
Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh135Free2018-08-25Windows Process Creation: PowerShell Command Execution Hidden in DLL Invocation
Flags DLL-invoking Windows binaries whose command lines include PowerShell execution strings.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2018-08-25Windows: .NET Reflection Attempt to Disable AMSI via amsiInitFailed
Alerts on Windows command lines referencing amsiInitFailed and .NET reflection patterns to disable AMSI scanning.
Markus Neis, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh442Free2018-08-17DNS TXT Answers Containing Command Execution Keywords (IEX, Invoke-Expression, cmd.exe)
Alerts on DNS TXT answers containing IEX/Invoke-Expression or cmd.exe strings indicative of execution-oriented payloads.
Markus Neis, Huntrule TeamNetworkdnsHigh133Free2018-08-08PowerShell NTFS Alternate Data Stream Writes via set-content/add-content
Alerts on PowerShell Set/Add-Content operations that specify -Stream, indicating potential NTFS Alternate Data Stream writes.
Sami Ruohonen, Huntrule TeamWindowsps_scriptHigh262Free2018-07-24Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
Markus Neis, Huntrule TeamWindowsfile_eventHigh203Free2018-07-24Windows Registry Explorer Run Key Persistence Pointing to Suspicious Paths
Alerts on writes to the Explorer Run policy registry key with details pointing to suspicious filesystem paths.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsregistry_setHigh122Free2018-07-18Windows Registry Events: CMSTP Execution via cmmgr32.exe TargetObject
Flags registry events referencing \cmmgr32.exe, consistent with CMSTP-related execution behavior on Windows.
Nik Seetharaman, Huntrule TeamWindowsregistry_eventHigh91Free2018-07-16