Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,256 rules
Windows: rundll32.exe launched by explorer.exe parent process
Alerts when explorer.exe spawns rundll32.exe with specific command-line characteristics on Windows.
CD_ROM_, Huntrule TeamWindowsprocess_creationMedium205Free2022-05-21Windows PowerShell Script Proxy Execution via CL_mutexverifiers.ps1
Alerts on PowerShell being launched with CL_mutexverifiers that proxies additional script execution.
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, frack113, Huntrule TeamWindowsprocess_creationMedium60Free2022-05-21PowerShell Assembly Loading via CL_LoadAssembly.ps1 Functions
Alerts on PowerShell command lines that call LoadAssemblyFromPath/LoadAssemblyFromNS in CL_LoadAssembly.ps1 context.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium143Free2022-05-21Windows AnyDesk Executed from Suspicious Directory
Alerts on AnyDesk execution from non-standard folders on Windows, indicating potential remote access abuse.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh308Free2022-05-20Windows PowerShell Base64 Encoded Commands Containing Invoke- ( -e )
Flags PowerShell executions using the -e encoded command flag with Base64 patterns consistent with an Invoke- call.
pH-T (Nextron Systems), Harjot Singh, @cyb3rjy0t, Huntrule TeamWindowsprocess_creationHigh131Free2022-05-20Windows grpconv Utility Execution with Output Option
Alerts on Windows process command lines invoking GrpConv with -o, potentially for .grp conversion or persistence.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-05-19Windows Office Applications Downloading Files via HTTP/HTTPS
Detects Office binaries invoked with command lines containing http/https, indicating potential arbitrary file download.
Nasreddine Bencherchali (Nextron Systems), Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationHigh71Free2022-05-17Windows Event Log Cleared (EventID 104, Microsoft-Windows-Eventlog)
Alerts when Microsoft-Windows-Eventlog reports Event ID 104 for core event log channels, indicating log clearing.
Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowssystemHigh376Free2022-05-17Windows: Process creation of TTDInject.exe (ttdinject.exe) for Time Travel Debugging
Alerts on Windows process creation for ttdinject.exe (TTDInject.EXE), a time travel debugging component.
frack113, Huntrule TeamWindowsprocess_creationMedium152Free2022-05-16Windows gpscript.exe Executes Group Policy Logon/Startup Scripts
Flags gpscript.exe running with /logon or /startup, suggestive of Group Policy script execution abuse.
frack113, Huntrule TeamWindowsprocess_creationMedium121Free2022-05-16Windows IEExec.EXE Download-and-Execute via Process Creation
Flags IEExec.exe executions that reference HTTP/HTTPS URLs for download-and-execute behavior.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh346Free2022-05-16Windows: File Download via CertOC.exe Using -GetCACAPS HTTP
Flags CertOC.exe launched with -GetCACAPS and an http URL, indicating a remote file retrieval attempt.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-05-16Windows Remote Thread Creation via Ttdinject.exe Proxy
Alerts on Windows create-remote-thread events initiated by Ttdinject.exe used as a proxy.
frack113, Huntrule TeamWindowscreate_remote_threadHigh122Free2022-05-16Windows Process Creation: reg.exe Adds Winlogon SpecialAccounts Userlist Value 0
Flags reg.exe command lines that add SpecialAccounts Userlist with /d 0 to hide accounts from the logon screen.
"@Kostastsale, TheDFIRReport, Huntrule Team"Windowsprocess_creationMedium70Free2022-05-14Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)
Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical409Free2022-05-12