Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,240 rules
Suspicious wuauclt.exe Process Creation on Windows with Empty Command-Line Flags
Alert on Windows Update Agent wuauclt.exe launches that have command lines ending with no flags/arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh82Free2022-02-26Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Alerts on processes launched from \Users\Public that execute common scripting/shell binaries or command-line markers.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh282Free2022-02-25Windows: ScreenConnect Client Service Spawning Suspicious Utility Commands
Alerts when ScreenConnect run.cmd leads to child processes like cmd.exe, PowerShell, curl, or other utilities.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @Kostastsale, Huntrule TeamWindowsprocess_creationMedium123Free2022-02-25Windows process creation: CrackMapExec execution via characteristic command-line flags
Alerts on Windows process creation showing CrackMapExec-style command-line flags for local auth and module execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh226Free2022-02-25Windows MSExchangeMailboxReplication .aspx/.asp File Writes Indicating Web Shell Upload
Alerts when MSExchangeMailboxReplication.exe writes .asp or .aspx files on Windows, indicating potentially malicious server-side script drops.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh3210Free2022-02-25Windows Process Creation: Hermetic Wiper–style Postgres/PowerShell Command-Line Patterns
Flags Windows process creation with wiper-like PowerShell comsvcs MiniDump and related command-line/paths.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh143Free2022-02-25Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Flags Windows process creation command-line patterns consistent with BlackByte ransomware techniques.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh3110Free2022-02-25Windows Registry: Disable CrashDump via CrashControl DWORD value
Alerts on registry changes that disable Windows crash dumps by writing 0x00000000 to CrashControl.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsregistry_setMedium371Free2022-02-24Windows Scheduled Task Creation via schtasks with Suspicious Command-Line Patterns
Flags schtasks.exe /Create commands containing suspicious interpreter, encoding, hidden execution, or unusual path/script components.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh432Free2022-02-23Windows explorer.exe spawned with /NOUACCHECK flag for UAC bypass behavior
Alerts on explorer.exe executions that include /NOUACCHECK, indicating potential bypass of UAC checks for child processes.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh113Free2022-02-23Windows scheduled task creation via schtasks.exe from suspicious parent path
Flags schtasks.exe /Create when spawned from temp or user-writable parent directories on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2022-02-23Windows Schtasks.exe Task Creation Targeting Suspicious Paths or Env Variables
Alerts when schtasks.exe creates tasks whose target path/arguments reference suspicious folders or common environment variables.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium161Free2022-02-21Windows CHCP Console Code Page Lookup Triggered From cmd.exe
Flags cmd.exe-launched chcp.com executions likely used to query system code page/locale for discovery.
_pete_0, TheDFIRReport, Huntrule TeamWindowsprocess_creationMedium192Free2022-02-21Suspicious Reset-ComputerMachinePassword Usage via PowerShell on Windows
Detects PowerShell executions of Reset-ComputerMachinePassword that may indicate attempts to alter domain computer account authentication.
frack113, Huntrule TeamWindowsps_moduleMedium134Free2022-02-21Windows Process Execution of Tor or Tor Browser (tor.exe / Firefox-based)
Flags Windows execution of tor.exe or Tor Browser’s bundled Firefox from the expected installation path.
frack113, Huntrule TeamWindowsprocess_creationHigh112Free2022-02-20