Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows schtasks.exe Scheduled Task Creation by Non-Microsoft Office Integration
Alerts on schtasks.exe /create executions indicating scheduled task creation, with exclusions for Office integrator-related cases.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow237Free2019-01-16Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
juju4, Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium155Free2019-01-16Windows Process Execution from Unusual System Locations
Alerts on Windows process launches where the executable path is in or contains unusual directories like RECYCLER or SystemVolumeInformation.
juju4, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium334Free2019-01-16Windows Suspicious rasdial.exe Process Execution
Flags Windows process executions of rasdial.exe by matching process image names ending with rasdial.exe.
juju4, Huntrule TeamWindowsprocess_creationMedium165Free2019-01-16Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix), Huntrule TeamWindowsprocess_creationHigh306Free2019-01-16PowerShell Spawned by wscript.exe or cscript.exe on Windows
Flags PowerShell launched by Windows script engines (wscript/cscript), excluding specific Health Service State activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium119Free2019-01-16Windows PowerShell execution with download-related command line patterns
Alerts when PowerShell is started with command-line fragments indicative of downloading remote content.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationMedium82Free2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
John Lambert (rule), Huntrule TeamWindowsprocess_creationHigh121Free2019-01-16Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium175Free2019-01-16Windows Process Reconnaissance via net.exe Group/Account Queries
Alerts on Windows net.exe commands querying groups and accounts via domain/local group and /do-related flags.
Florian Roth (Nextron Systems), omkar72, @svch0st, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium121Free2019-01-16Windows Process Creation: Suspicious Children Spawned by mshta.exe
Flags mshta.exe spawning command, script, or utility processes commonly abused for executing malicious HTA payloads.
Michael Haag, Huntrule TeamWindowsprocess_creationHigh433Free2019-01-16Windows Java Process Started with Remote Debugging Enabled for Non-Localhost Connections
Identifies Java processes started with JDWP dt_socket remote debugging on a non-localhost address.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium344Free2019-01-16Windows Cmdkey.EXE Cached Credential Reconnaissance
Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.
jmallette, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2019-01-16Windows cmd.exe Command Line with URL and %AppData% Indicators
Alerts on cmd.exe executions whose command line includes a URL pattern (http/https) and %AppData%.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium30Free2019-01-16Windows Script File Execution via Wscript/Cscript Using Script File Extensions
Flags wscript.exe or cscript.exe executing common script file types via command-line extensions on Windows.
Michael Haag, Huntrule TeamWindowsprocess_creationMedium20Free2019-01-16