Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Remote Thread Injection Indicators via Process StartAddress Suffixes
Flags Windows CreateRemoteThread events with StartAddress suffixes 0B80, 0C7C, or 0C88.
Olaf Hartong, Florian Roth (Nextron Systems), Aleksey Potapov, oscd.community, Huntrule TeamWindowscreate_remote_threadHigh365Free2018-11-30Zeek SMB spoolss Named Pipe (IPC$) Access
Flags Zeek SMB events accessing the spoolss named pipe via IPC$.
OTR (Open Threat Research), @neu5ron, Huntrule TeamZeeksmb_filesMedium298Free2018-11-28Windows Service Control Manager: WerFaultSvc Installed via Service Creation (Event ID 7045)
Alerts on Windows Event 7045 service creation for "WerFaultSvc" as an indicator of dropper-style persistence.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemCritical373Free2018-11-23Windows: Suspicious Executable Downloads Missing File Metadata Fields
Alerts when a process launches from Downloads with missing/placeholder file metadata (Description, FileVersion, Product, or Company).
Markus Neis, Sander Wiebing, Huntrule TeamWindowsprocess_creationMedium121Free2018-11-22Windows Process Creation—CommandLine Indicators for APT29 2018 Phishing Campaign
Alerts on Windows command-line substrings seen in the 2018 APT29 phishing campaign indicators.
Florian Roth (Nextron Systems), @41thexplorer, Huntrule TeamWindowsprocess_creationCritical83Free2018-11-20Windows File Events: Detect ds7002*.lnk, .pdf, and .zip Indicators
Flags Windows file events with target filenames containing ds7002.lnk, ds7002.pdf, or ds7002.zip.
"@41thexplorer, Huntrule Team"Windowsfile_eventCritical101Free2018-11-20Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Flags PowerShell script blocks containing Base64 strings matching known shellcode markers.
David Ledbetter (shellcode), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh113Free2018-11-17Windows: Potential Kerberoasting SPN Enumeration via setspn.exe
Detects Windows setspn.exe runs with SPN query command-line parameters that may indicate Kerberoasting preparation.
Markus Neis, keepwatch, Huntrule TeamWindowsprocess_creationMedium405Free2018-11-14Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2018-10-30Windows: Local user account creation via net.exe or net1.exe
Alerts on net.exe/net1.exe launching with "user" and "add" to create local accounts on Windows.
Endgame, JHasenbusch (adapted to Sigma for oscd.community), Huntrule TeamWindowsprocess_creationMedium40Free2018-10-30Antivirus Web Shell Signature Matches Across ASP, JSP, PHP, Perl, and VBS
Alerts on AV signatures indicating web shells/backdoors (ASP/JSP/PHP/Perl/VBS/Webshell) to support fast investigation of persistence.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusHigh248Free2018-09-09Antivirus alerts for suspicious file paths and web/script file extensions
Alerts on AV hits involving suspicious file locations and web/script-related extensions.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusHigh82Free2018-09-09Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Triggers on AV signatures matching PWS* or known credential-dumping tool strings indicating potential password theft activity.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical93Free2018-09-09Antivirus signature match for exploitation framework indicators
Alerts when AV signature names contain indicators tied to exploitation frameworks and related backdoors.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical201Free2018-09-09Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Flags PowerShell (powershell.exe/pwsh) process executions with command-line indicators consistent with XOR/obfuscated scripting.
Sami Ruohonen, Harish Segar, Tim Shelton, Teymur Kheirkhabarov, Vasiliy Burov, oscd.community, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium247Free2018-09-05