Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,606 rules
Windows Ping Hex IP Usage via Command Line
Flags ping.exe executions that pass a hex-encoded IPv4 address (0x????????) in the command line on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh91Free2018-03-23Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Alerts on Windows service installation events for persistence-related scheduled services named SC Scheduled Scan or UpdatMachine.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssystemCritical91Free2018-03-23Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowssecurityCritical216Free2018-03-23Windows Registry Persistence via UMe/UT Run Keys
Alerts on Windows registry changes to UMe/UT run key subpaths associated with persistence.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsregistry_eventCritical153Free2018-03-23Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Alerts when scheduled task and Service.exe processes launch autoit3.exe that runs nslookup TXT queries from a temp staging path.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationCritical229Free2018-03-23Windows Service Control Manager flags smbexec.py-style service installation via suspicious ImagePath
Flags suspicious Windows service installations matching a specific service name and BAT/delete command patterns in Event 7045.
Omer Faruk Celik, Huntrule TeamWindowssystemHigh83Free2018-03-20Windows Security: Registry NetNTLM Downgrade Configuration Changes
Alerts on Windows registry changes that weaken NetNTLM/NTLM security settings via LSA compatibility and restriction values.
Florian Roth (Nextron Systems), wagga, Huntrule TeamWindowssecurityHigh118Free2018-03-20Windows Process Creation: taskmgr.exe launched in LOCAL_SYSTEM context
Flags taskmgr.exe process creation when initiated under a LOCAL_SYSTEM-equivalent user context string.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh31Free2018-03-18Windows Suspicious RDP Session Redirect via tscon.exe /dest:rdp-tcp#
Alerts on Windows process executions using tscon.exe-style RDP redirection to an "rdp-tcp#" destination.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2018-03-17Windows: Detect tscon.exe launched under SYSTEM context
Alerts on tscon.exe starting under a SYSTEM-associated user context based on Windows process creation logs.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh239Free2018-03-17Windows Registry Image File Execution Options Debugger Backdoor (sethc.exe/utilman.exe/osk.exe)
Alerts on registry Debugger hijacks for Windows login/accessibility binaries using Image File Execution Options.
Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsregistry_eventCritical404Free2018-03-15Windows Backdoor Execution via Sticky Keys and Login-Screen Accessibility Tools
Flags winlogon.exe spawning command/script tools referencing login-screen accessibility binaries (sethc.exe, utilman.exe, osk.exe, etc.).
Florian Roth (Nextron Systems), @twjackomo, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationCritical81Free2018-03-15Windows Process Creation with taskmgr.exe as Parent Process
Flags process creation where taskmgr.exe is the parent, excluding a few known benign child process images.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow62Free2018-03-13Windows WMI Script Event Consumer Execution via scrcons.exe
Flags scrcons.exe starting under svchost.exe, indicating WMI script event consumer execution that can support persistence.
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium217Free2018-03-07Windows WMI Persistence via wbemcons.dll Loaded by WmiPrvSE.exe
Identifies WmiPrvSE.exe loading wbemcons.dll, a behavior consistent with WMI command line event consumer persistence on Windows.
Thomas Patzke, Huntrule TeamWindowsimage_loadHigh63Free2018-03-07