Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,252 rules
Windows Security: Password-Protected ZIP Opened with Suspicious Filename Indicators
Alerts when Windows opens password-protected ZIP contents with filenames commonly tied to invoices, orders, payments, and deliveries.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityHigh217Free2022-05-09Windows Security Event 5379: Password-Protected ZIP Opened
Flags Windows EventID 5379 indicating a password-protected ZIP archive was opened.
Florian Roth (Nextron Systems), Huntrule TeamWindowssecurityMedium132Free2022-05-09Windows: ie4uinit.exe Used from Non-Standard Current Directory
Flags ie4uinit.exe runs whose CurrentDirectory is outside expected system paths, indicating potential LOLBIN misuse.
frack113, Huntrule TeamWindowsprocess_creationMedium415Free2022-05-07Windows Process Creation: Ilasm.EXE Used to Compile IL to EXE/DLL
Alerts when Ilasm.EXE is run with /exe or /dll to compile IL into a Windows binary.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium142Free2022-05-07Windows Process Creation: Cobalt Strike module/command strings entered in cmd.exe
Alerts when cmd.exe command lines include Cobalt Strike module/command strings.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh434Free2022-05-06Windows Process Command Line: Accidental Cobalt Strike Commands in cmd.exe
Flags cmd.exe executions whose command lines include known Cobalt Strike command terms.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationHigh60Free2022-05-06Windows Raspberry Robin Execution via cmd.exe Parent and External-File Payload
Flags cmd.exe with /r from external media launching msiexec.exe /q that includes an HTTP/HTTPS payload URL.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh1810Free2022-05-06Windows: Raspberry Robin Command Execution via fodhelper.exe and rundll32/regsvr32
Flags Windows process-spawn chains where fodhelper.exe runs rundll32/regsvr32 with Raspberry Robin-style command-line patterns.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh388Free2022-05-06Windows Process Creation: Suspicious Child Processes Spawned by regsvr32.exe
Alerts when regsvr32.exe spawns suspicious child processes like PowerShell, mshta, or scripting utilities.
elhoim, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2022-05-05Windows: Registry Set by Rundll32 for Screen Saver Execution via SCRNSAVE.EXE
Flags Windows registry sets where Rundll32 points SCRNSAVE.EXE to a .scr file.
Jose Luis Sanchez Martinez (@Joseliyo_Jstnk), Huntrule TeamWindowsregistry_setMedium162Free2022-05-04Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Detects rundll32.exe launching davclnt.dll DavSetCookie with HTTP and spoolss/srvsvc pipe parameters associated with NTLM coercion.
Elastic (idea), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2022-05-04Linux: Detects Nimbuspwn-related exploit strings targeting CVE-2022-29799/CVE-2022-27800
Detects Linux keyword patterns suggesting Nimbuspwn-style traversal attempts via networkd-dispatcher error handling.
Bhabesh Raj, Huntrule TeamLinux—High349Free2022-05-04Windows Registry: Service configured with image path in suspicious public/temp folders
Detects Windows service ImagePath pointing to Users\Public, Perflogs, ADMIN$, or Temp based on registry_set events.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowsregistry_setHigh141Free2022-05-02Windows: PrintBrm.exe ZIP extraction or creation via command-line parameters
Flags PrintBrm.exe executions that include '-f' and '.zip', consistent with ZIP creation or extraction behavior.
frack113, Huntrule TeamWindowsprocess_creationHigh132Free2022-05-02Windows JScript Compiler (jsc.exe) Process Execution
Identifies execution of jsc.exe (JScript Compiler) from Windows process creation logs.
frack113, Huntrule TeamWindowsprocess_creationLow185Free2022-05-02