Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Process Creation: Suspicious GUP.exe Execution from Non-Notepad++ Directories
Alerts on GUP.exe executions from unexpected directories on Windows, excluding known Notepad++ updater paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh168Free2019-02-06Windows Security Event 4616 for System Time Changes by Non-Service Accounts
Flags Windows Event 4616 system time changes when made by processes outside svchost.exe and common virtualization agents.
"@neu5ron, Huntrule Team"WindowssecurityLow82Free2019-02-05Windows Remote Thread Creation via CACTUSTORCH Using Script/Office/Rundll Host Images
Alerts on SysWOW64 remote thread creation initiated by script host or Office binaries consistent with CACTUSTORCH behavior.
"@SBousseaden (detection), Thomas Patzke (rule), Huntrule Team"Windowscreate_remote_threadHigh131Free2019-02-01Chafer malware C2 URLs with /asp.asp?ui= pattern over HTTP proxy
Flags proxy HTTP requests containing the C2 URI pattern /asp.asp?ui= associated with Chafer behavior.
Florian Roth (Nextron Systems), Huntrule Team—proxyHigh127Free2019-01-31Windows netsh.exe Used to Create RDP (3389) Port Forwarding
Flags netsh.exe executions that appear to set up RDP (3389) port forwarding.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsprocess_creationHigh302Free2019-01-29Windows netsh.EXE Adds Portproxy v4-to-v4 Forwarding Rule
Flags netsh.exe command lines that add portproxy v4-to-v4 forwarding rules on Windows.
Florian Roth (Nextron Systems), omkar72, oscd.community, Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium83Free2019-01-29Windows Firewall Rule Added via netsh.exe
Flags netsh.exe executions that add Windows firewall rules, indicating potential attacker-controlled network access changes.
Markus Neis, Sander Wiebing, Huntrule TeamWindowsprocess_creationMedium389Free2019-01-29Windows RDP Logon Using Localhost IP Address
Alerts on successful Windows logons (EventID 4624, LogonType 10) originating from localhost IPs.
Thomas Patzke, Huntrule TeamWindowssecurityHigh122Free2019-01-28Apache thread assertion error in error.log
Flags Apache error log entries that include a pthread thread-priority assertion failure message.
Florian Roth (Nextron Systems), Huntrule TeamWebapacheMedium375Free2019-01-22Windows Registry: New Security Support Provider (SSP) added to LSA configuration
Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.
iwillkeepwatch, Huntrule TeamWindowsregistry_eventHigh102Free2019-01-18Windows Script Execution from User-Accessible Paths via WScript, CScript, or MSHTA
Alerts when WScript/CScript/MSHTA launches scripts or HTAs referenced from user and temp directories.
Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems), Dave Johnson, Huntrule TeamWindowsprocess_creationMedium52Free2019-01-16Windows Process Creation Attempt Using wmic.exe process call create
Alerts on Windows process creation attempts invoking wmic.exe with “process call create”, a common pattern for WMI-based execution.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Huntrule TeamWindowsprocess_creationMedium30Free2019-01-16Windows Suspicious Child Processes Spawned by Web Server Executables
Alerts when web server processes (e.g., nginx/httpd/caddy/php/tomcat) spawn suspicious Windows command/scripting executables.
Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2019-01-16Windows Process Execution From Uncommon or Sensitive Directories
Alerts on process executions from uncommon/sensitive Windows directories, excluding specific IBM and Citrix updater paths.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh132Free2019-01-16Windows Shim Database Persistence via sdbinst.exe with .sdb Payload
Alerts when sdbinst.exe runs and references a .sdb shim database, indicating potential shim-based persistence.
Markus Neis, Huntrule TeamWindowsprocess_creationMedium63Free2019-01-16