Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,281 rules
Windows Process Creation: reg.exe Adds or Copies SafeBoot Registry Keys
Flags reg.exe with add/copy used against SafeBoot registry keys in Windows process creation logs.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh463Free2022-09-02Windows Process Execution of Fast Reverse Proxy (FRP) frpc.exe or frps.exe
Alerts on Windows execution of FRP components (frpc.exe/frps.exe) with FRP indicators via command line or known hashes.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh429Free2022-09-02Windows: Detect Ldifde.exe LDAP import (-i -f) usage
Flags Ldifde.exe being run with LDAP import parameters (-i and -f) that may trigger remote content retrieval.
"@gott_cyber, Huntrule Team"Windowsprocess_creationMedium203Free2022-09-02Windows certutil.exe Initiates Network Connections to Common Service Ports
Alerts when certutil.exe initiates outbound network connections to ports 80, 135, 443, or 445 on Windows.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh198Free2022-09-02Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
Nasreddine Bencherchali (Nextron Systems), frack113 , X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2022-09-01Windows Process Creation: Suspicious ShellExec_RunDLL Command-Line Usage
Detects Windows command lines containing ShellExec_RunDLL along with other suspicious execution indicators.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh60Free2022-09-01Windows net.exe Commands Manipulating Built-in Default Accounts (administrator/guest)
Flags net.exe/net1.exe process creation when command lines reference built-in Administrator/guest/default accounts with suspicious active/disable context.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh284Free2022-09-01Windows Suspicious cmd.exe Launch After net use Mounting WebDAV Share
Flags cmd.exe command lines that mount an Internet WebDAV share with net use and immediately execute content from DavWWWRoot.
pH-T (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2022-09-01Windows Suspicious Process Execution Using GUID-Like Folder Names in %TEMP% or AppData
Hunts Windows processes whose command lines reference GUID-named folders in user AppData/Temp locations.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow100Free2022-09-01Windows schtasks.exe scheduled task creation or modification with high privileges on suspicious schedule types
Flags schtasks.exe commands that create/modify tasks to run on ONLOGON/ONSTART/ONCE/ONIDLE with SYSTEM or HIGHEST privileges.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium3210Free2022-08-31Windows Process Creation: Wscript.Shell.Run keyword sequence in CommandLine
Alerts on Windows command lines containing Wscript.Shell.Run keyword sequence, suggesting script-driven shell execution.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2022-08-31Windows Process Creation: DefenderCheck.exe Execution (PUA/Signature Evasion)
Alerts on execution of DefenderCheck.exe/description to identify potential AV signature probing and evasion preparation.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh421Free2022-08-30Windows Network Connection from Cmstp.EXE (Outbound)
Alerts on outbound network connections initiated by cmstp.exe, which is uncommon and may indicate process misuse.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh60Free2022-08-30Windows: cmstp.exe Loading DLL/OCX from Suspicious Paths
Alerts when cmstp.exe loads DLL/OCX from suspicious directories on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsimage_loadHigh82Free2022-08-30Windows RTCore64 Service Installation via Service Control Manager (Event ID 7045)
Alerts on creation of the RTCore64 Windows service via Service Control Manager Event ID 7045.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh101Free2022-08-30