Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process CommandLine contains -export dll_u (DLL export function load)
Flags Windows processes that invoke a DLL export function named dll_u via command-line export arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical188Free2019-03-04Windows Security: ScheduledDefrag Task Deactivated via Event ID 4701
Flags Windows EventID 4701 activity that disables the ScheduledDefrag scheduled task.
Florian Roth (Nextron Systems), Bartlomiej Czyz (@bczyz1), Huntrule TeamWindowssecurityMedium395Free2019-03-04Windows ScheduledDefrag task removal via schtasks /delete and /change
Detects schtasks.exe commands that delete or change the ScheduledDefrag scheduled task.
Florian Roth (Nextron Systems), Bartlomiej Czyz (@bczyz1), Huntrule TeamWindowsprocess_creationMedium336Free2019-03-04Windows: certutil.exe File Encoding to Base64 Using the -encode Flag
Alerts on Windows certutil.exe executions using -encode to base64-encode a file.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2019-02-24Windows: PowerShell-triggered HTA retrieval and execution with registry and process disruption
Alerts on Windows process creation where PowerShell uses mshta over HTTP and includes .hta, registry query, and cmd.exe termination.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh411Free2019-02-24Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
vburov, Huntrule TeamWindowsprocess_creationLow142Free2019-02-23Windows mshta.exe Execution Using Non-HTA File Extensions
Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.
Diego Perez (@darkquassar), Markus Neis, Swisscom (Improve Rule), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2019-02-22Windows: RDP Session Startup Folder Backdoor via tsclient Share Targeting Startup Path
Flags mstsc.exe activity writing to the Windows Startup folder, indicating potential RDP session backdoor placement.
Samir Bousseaden, Huntrule TeamWindowsfile_eventHigh143Free2019-02-21Windows svchost RDP via Reverse SSH Loopback Tunnel to 127.0.0.0/8:3389
Flags svchost.exe opening RDP (TCP 3389) connections to loopback, consistent with tunneled reverse access behavior.
Samir Bousseaden, Huntrule TeamWindowsnetwork_connectionHigh2010Free2019-02-16Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh103Free2019-02-16Windows Registry Persistence Attempt Using AppDataLow Ursnif-Related Path
Alerts on Windows registry key additions matching a Ursnif-associated TargetObject path.
megan201296, Huntrule TeamWindowsregistry_addHigh132Free2019-02-13Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh464Free2019-02-11Windows PowerShell Script Block Matches Common Reflection and Injection Keywords
Alerts on PowerShell script block text containing reflection, dynamic assembly loading, and injection-related keywords.
Florian Roth (Nextron Systems), Perez Diego (@darkquassar), Tuan Le (NCSGroup), Huntrule TeamWindowsps_scriptMedium63Free2019-02-11Windows Process Creation: Suspicious calc.exe Command-Line Usage Outside System Locations
Alerts on suspicious calc.exe launches via command-line parameters or execution from non-standard Windows directories.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh425Free2019-02-09Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)
Alerts on bcdedit.exe executions with command-line options consistent with boot configuration tampering.
"@neu5ron, Huntrule Team"Windowsprocess_creationMedium112Free2019-02-07