Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,345 rules
Windows Process Creation: Sysmon.exe as Parent of Spawned Process
Alerts when Sysmon.exe/Sysmon64.exe is the parent of a new process, a potentially suspicious execution chain on Windows.
Florian Roth (Nextron Systems), Tim Shelton (fp werfault), Huntrule TeamWindowsprocess_creationHigh102Free2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh153Free2022-11-09Windows System: Kerberos KDC RC4-HMAC downgrade exploit attempts (CVE-2022-37966)
Identifies Windows Kerberos KDC error events tied to RC4-HMAC downgrade/auth negotiation exploitation behavior (CVE-2022-37966).
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh148Free2022-11-09Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
Tim Rauch, Janantha Marasinghe, Elastic (original idea), Huntrule TeamWindowsprocess_creationHigh122Free2022-11-08Windows File Creation: Suspicious LNK Double-Extension Targeted by Document/Image Prefixes
Alerts on Windows-created filenames that end in .lnk while containing hidden-looking double extensions (e.g., .doc. .pdf.)
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsfile_eventMedium103Free2022-11-07Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Identifies Windows successful logons consistent with potential access token impersonation using Advapi and Negotiate.
Michaela Adams, Zach Mathis, Huntrule TeamWindowssecurityMedium60Free2022-11-06Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
Ilya Krestinichev, Huntrule TeamWindowsprocess_creationHigh131Free2022-11-03Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh152Free2022-11-03Linux network connections to ngrok tunneling endpoints
Alerts on Linux connections to ngrok tunnel domains, which may indicate tunneling-based C2 or exfiltration.
Florian Roth (Nextron Systems), Huntrule TeamLinuxnetwork_connectionHigh101Free2022-11-03Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh337Free2022-11-01Windows Scheduled Task Creation with GUID-like Task Name
Alerts on schtasks.exe creating scheduled tasks whose /TN value is wrapped GUID-like braces.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium153Free2022-10-31Windows Image Load: Uncommon VSSAPI DLL (vssapi.dll) by Suspicious Executables
Alerts when uncommon processes load vssapi.dll, a Shadow Copy–related DLL, using image load telemetry with path-based exclusions.
frack113, Huntrule TeamWindowsimage_loadHigh80Free2022-10-31Windows Remote Utilities Host Service Installation via Service Control Manager (EventID 7045)
Alerts on Windows Event 7045 when a "Remote Utilities - Host" service is installed from rutserv.exe -service.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium141Free2022-10-31Windows Service Installation via NetSupport Manager (Event ID 7045)
Flags Windows service creation for NetSupport Manager Client32 (client32.exe) using Service Control Manager Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemMedium162Free2022-10-31Windows: vsls-agent.exe Executed With --agentExtensionPath Suspicious Library Load
Flags vsls-agent.exe launched with --agentExtensionPath, suggesting a potentially suspicious external extension/library load.
bohops, Huntrule TeamWindowsprocess_creationMedium448Free2022-10-30