Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh395Free2019-05-22Potential BearLPE Exploitation via Windows Task Scheduler schtasks.exe DACL Change
Flags schtasks.exe executions with /change, /TN, /RU, and /RP, consistent with task modification tied to BearLPE attempts.
Olaf Hartong, Huntrule TeamWindowsprocess_creationHigh142Free2019-05-22WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
Patryk Prauze - ING Tech, Huntrule TeamWindowsprocess_accessHigh239Free2019-05-20Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
Alec Costello, Huntrule TeamWindowsps_scriptHigh248Free2019-05-16Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.
Markus Neis, Huntrule TeamWindowsnetwork_connectionHigh71Free2019-05-15Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh127Free2019-04-20Windows Local User Creation (Security Event 4720)
Flags Windows Security Event ID 4720 indicating a local user account was created.
Patrick Bareiss, Huntrule TeamWindowssecurityLow3210Free2019-04-18Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowswmi_eventHigh113Free2019-04-15Windows Registry: Create/Modify CLSID/AppX keys associated with OceanLotus decoy paths
OceanLotus Registry Activity
megan201296, Jonhnathan Ribeiro, Huntrule TeamWindowsregistry_eventCritical121Free2019-04-14Windows: Suspicious Service Installation via Registry ImagePath Outside system32
Alerts on NalDrv/PROCEXP152 service ImagePath registry entries configured outside the expected system32 driver path.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsregistry_setMedium42Free2019-04-08Windows Suspicious PROCEXP152.sys Creation in Local Temp Folder
Flags creation of PROCEXP152.sys in AppData\Local\Temp, excluding events from common Sysinternals executables.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsfile_eventMedium209Free2019-04-08Windows Security Event 4673: SeLoadDriverPrivilege Use by Non-Whitelisted Processes
Flags Windows Event 4673 instances where SeLoadDriverPrivilege is exercised, suggesting attempts to load or unload kernel-mode drivers.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowssecurityMedium108Free2019-04-08Linux Command Lines Creating Symlink to /etc/passwd
Alerts on Linux command lines attempting to create symlinks to /etc/passwd via ln -s/ln -f patterns.
Florian Roth (Nextron Systems), Huntrule TeamLinux—High91Free2019-04-05WmiPrvSE.exe Spawned PowerShell Child Process on Windows
Alerts on PowerShell spawning from WmiPrvSE.exe, a possible indicator of WMI-based remote execution.
Markus Neis @Karneades, Huntrule TeamWindowsprocess_creationMedium73Free2019-04-03Windows Security 5145 Network Share Access to Sensitive File Extensions
Alerts when Windows users access network-shared files with extensions commonly targeted for credential or data collection.
Samir Bousseaden, Huntrule TeamWindowssecurityMedium362Free2019-04-03