Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
38 rules
Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
Alerts on certutil.exe runs with URL/HTTP-related flags indicative of remote file download.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2023-02-15Windows certutil.exe Base64/Hex Decode via -decode or -decodehex Flags
Flags certutil.exe use for decoding base64 or hex data via -decode or -decodehex on Windows.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh122Free2023-02-15Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh103Free2023-01-18Windows certutil.exe Initiates Network Connections to Common Service Ports
Alerts when certutil.exe initiates outbound network connections to ports 80, 135, 443, or 445 on Windows.
frack113, Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh208Free2022-09-02Suspicious Child Process Spawning by PowerShell on Windows
Alerts when PowerShell spawns potentially suspicious child binaries (e.g., certutil, mshta, wmic, rundll32), with exclusions for known benign patterns.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationMedium100Free2022-04-26Windows LOLBIN Execution From Abnormal Drive (calc, certutil, mshta, regsvr32, rundll32)
Flags Windows LOLBIN execution when process CurrentDirectory is not empty/null and contains C:\, indicating unusual launch context.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Angelo Violetti - SEC Consult '@angelo_violetti', Aaron Herman, Huntrule TeamWindowsprocess_creationMedium92Free2022-01-25Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
Maxim Pavlunin, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2020-04-01Windows: certutil.exe File Encoding to Base64 Using the -encode Flag
Alerts on Windows certutil.exe executions using -encode to base64-encode a file.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium100Free2019-02-24