Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process Creation: WSReset.exe Used with Non-CONHOST Child Process
Alerts when wsreset.exe spawns a process other than conhost.exe, a potential UAC-bypass precursor.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Florian Roth, Huntrule TeamWindowsprocess_creationHigh315Free2019-10-24Windows: Detect Fodhelper.exe spawned processes indicative of UAC bypass
Flags process creation where the parent is Fodhelper.exe, a common UAC bypass execution pattern on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2019-10-24Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Alerts when cmstp.exe is launched with INF installation and silent/auto options indicating a UAC-bypass style behavior.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh192Free2019-10-24Windows Process Creation: tapinstall.exe Execution
Alerts on tapinstall.exe being executed on Windows, excluding known VPN driver installer paths.
Daniil Yugoslavskiy, Ian Davis, oscd.community, Huntrule TeamWindowsprocess_creationMedium427Free2019-10-24Windows Process Creation: Web Request Cmdlets and CLI Tools Usage
Alerts on Windows CommandLine usage of web request cmdlets/tools like Invoke-WebRequest, Invoke-RestMethod, curl, wget, and BITS transfer.
James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium73Free2019-10-24Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
E.M. Anhaus, Tony Lambert, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh142Free2019-10-24Windows Process Creation: SoundRecorder audio capture using /FILE
Flags SoundRecorder.exe launches that include /FILE, indicating potential audio capture on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationMedium63Free2019-10-24Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationLow51Free2019-10-24Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium62Free2019-10-24Windows netsh Trace Start Command Execution
Flags netsh.exe launched with "trace" and "start", commonly used to begin a network trace capture on Windows.
Kutepov Anton, oscd.community, Huntrule TeamWindowsprocess_creationMedium237Free2019-10-24Windows Mshta.exe Launching JavaScript via Command Line
Detects Mshta.exe executions where the command line includes "javascript".
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh326Free2019-10-24Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Alerts when Hwp.exe launches gbb.exe, a suspicious child process pattern on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2019-10-24Windows hh.exe Execution Triggered by .chm Command Line
Flags hh.exe being executed with a command line referencing a .chm file on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community, Huntrule TeamWindowsprocess_creationLow93Free2019-10-24Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
E.M. Anhaus, Tony Lambert, oscd.community, omkar72, Huntrule TeamWindowsprocess_creationMedium221Free2019-10-24Windows Execution of dnscat2 and iodine DNS Exfiltration/Tunneling Tools
Flags Windows execution of DNS tunneling/exfiltration tools identified by iodine.exe or dnscat2 in process creation events.
Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh193Free2019-10-24