Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows PowerShell Suspicious Encoded Command-Line Execution
Alerts on PowerShell launched with encoded-command switches and embedded encoded content patterns in the command line.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, Anton Kutepov, oscd.community, Huntrule TeamWindowsprocess_creationHigh238Free2018-09-03Windows process creation: svchost.exe launched by sllauncher.exe for DLL side-loading
Flags AppData\Roaming-launched svchost.exe instances spawned by sllauncher.exe with -k, matching DLL side-loading execution behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical113Free2018-09-03Windows Process in Suspicious Folder Initiating Network Connections to File Sharing Domains
Alerts on outbound connections to file sharing domains from Windows executables running out of suspicious temp/recycle/task paths.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh423Free2018-08-30Windows LSASS process access blocked by Attack Surface Reduction (Windows Defender event 1121)
Alerts on windefend EventID 1121 for blocked access to lsass.exe, excluding common benign process callers.
Markus Neis, Huntrule TeamWindowswindefendHigh171Free2018-08-26Windows Registry Run Key Set to Executable in Suspicious Folder
Flags new Windows Run key values pointing to executables in suspicious folders, excluding known update/Spotify patterns.
Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsregistry_setHigh135Free2018-08-25Windows Process Creation: PowerShell Command Execution Hidden in DLL Invocation
Flags DLL-invoking Windows binaries whose command lines include PowerShell execution strings.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2018-08-25Windows: .NET Reflection Attempt to Disable AMSI via amsiInitFailed
Alerts on Windows command lines referencing amsiInitFailed and .NET reflection patterns to disable AMSI scanning.
Markus Neis, @Kostastsale, Huntrule TeamWindowsprocess_creationHigh422Free2018-08-17DNS TXT Answers Containing Command Execution Keywords (IEX, Invoke-Expression, cmd.exe)
Alerts on DNS TXT answers containing IEX/Invoke-Expression or cmd.exe strings indicative of execution-oriented payloads.
Markus Neis, Huntrule TeamNetworkdnsHigh133Free2018-08-08PowerShell NTFS Alternate Data Stream Writes via set-content/add-content
Alerts on PowerShell Set/Add-Content operations that specify -Stream, indicating potential NTFS Alternate Data Stream writes.
Sami Ruohonen, Huntrule TeamWindowsps_scriptHigh262Free2018-07-24Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
Markus Neis, Huntrule TeamWindowsfile_eventHigh203Free2018-07-24Web server access to WebLogic keystore JavaScript webshell URLs
Flags web requests attempting to access JavaScript content within a WebLogic keystore path.
Florian Roth (Nextron Systems), Huntrule Team—webserverCritical271Free2018-07-22Windows Registry Explorer Run Key Persistence Pointing to Suspicious Paths
Alerts on writes to the Explorer Run policy registry key with details pointing to suspicious filesystem paths.
Florian Roth (Nextron Systems), oscd.community, Huntrule TeamWindowsregistry_setHigh122Free2018-07-18Windows Registry Events: CMSTP Execution via cmmgr32.exe TargetObject
Flags registry events referencing \cmmgr32.exe, consistent with CMSTP-related execution behavior on Windows.
Nik Seetharaman, Huntrule TeamWindowsregistry_eventHigh71Free2018-07-16Windows CMSTP Process Spawning Child Process
Alerts on child processes spawned by Windows cmstp.exe, a common signal for CMSTP abuse.
Nik Seetharaman, Huntrule TeamWindowsprocess_creationHigh226Free2018-07-16Windows Process Access to cmlua.dll by CMSTP Connection Manager Profile Installer
Alerts on Windows process access events whose call trace includes cmlua.dll, indicating potential CMSTP-related execution.
Nik Seetharaman, Huntrule TeamWindowsprocess_accessHigh438Free2018-07-16