Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,172 rules
Windows Process Creation: Serv-U CVE-2021-35211 Exploitation Command Pattern
Alerts on Windows process commands that combine 'whoami' with Serv-U-specific execution path and temp batch patterns tied to CVE-2021-35211.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical231Free2021-07-14Windows ProtocolHandler.exe Download via Embedded URL Schemes
Flags ProtocolHandler.exe executions with ftp/http/https URLs that indicate automated downloading on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium132Free2021-07-13Windows PowerShell: AtomicTestHarness Invoke-ATHRemoteFXvGPUDisablementCommand Abuse
Alerts on Windows process command lines invoking AtomicTestHarnesses RemoteFXvGPUDisablement PowerShell execution.
frack113, Huntrule TeamWindowsprocess_creationHigh133Free2021-07-13Windows: InfDefaultInstall.exe .inf Execution
Flags Windows process executions of InfDefaultInstall.exe that include an .inf argument in the command line.
frack113, Huntrule TeamWindowsprocess_creationMedium141Free2021-07-13Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleHigh497Free2021-07-13Windows PowerShell ModuleContents Set to Get-VMRemoteFXPhysicalVideoAdapter
Alerts on PowerShell module creation embedding Get-VMRemoteFXPhysicalVideoAdapter, a potential precursor to RemoteFXvGPUDisablement.exe abuse.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspowershell-classicHigh402Free2021-07-13Windows Uninstall CrowdStrike Falcon Sensor via WindowsSensor.exe /uninstall /quiet
Flags Windows processes uninstalling CrowdStrike Falcon Sensor using WindowsSensor.exe with /uninstall and /quiet.
frack113, Huntrule TeamWindowsprocess_creationHigh173Free2021-07-12Windows Process: SyncAppvPublishingServer.exe Executes PowerShell via PowerShell-encoded command
Alerts when SyncAppvPublishingServer.exe is launched with a command-line pattern indicative of PowerShell code execution.
frack113, Huntrule TeamWindowsprocess_creationMedium166Free2021-07-12Windows Process Injection via Mavinject Using INJECTRUNNING Flag
Alerts on Windows process creation using Mavinject with /INJECTRUNNING, indicative of DLL injection into a running process.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh257Free2021-07-12Windows spoolsv.exe Child Process Execution Indicators
Flags suspicious process executions where spoolsv.exe (print spooler) spawns utility, scripting, or rundll32 children with high integrity.
Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule), Huntrule TeamWindowsprocess_creationHigh171Free2021-07-11Windows DNS Queries for IP Lookup Service Domains from Non-Browser Processes
Flags suspicious DNS lookups to IP-check API domains on Windows when they come from non-browser executables.
Brandon George (blog post), Thomas Patzke, Huntrule TeamWindowsdns_queryMedium193Free2021-07-08Windows Process Creation: MpCmdRun.exe Removing All Windows Defender Definitions
Flags MpCmdRun.exe launched to remove all Windows Defender definition files.
frack113, Huntrule TeamWindowsprocess_creationHigh151Free2021-07-07Windows Registry Defender Exclusions Path Set (Microsoft\Windows Defender\Exclusions)
Identifies registry updates that reference the Windows Defender Exclusions path, indicating potential defense impairment.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setMedium477Free2021-07-06Windows Defender Exclusions Added via Windefend (Event ID 5007)
Alerts on Windows Defender exclusion additions based on windefend Event ID 5007 configuration change events.
Christian Burkard (Nextron Systems), Huntrule TeamWindowswindefendMedium223Free2021-07-06Windows windefend: Detect Tamper Protection blocks changes to Microsoft Defender settings
Flags Defender tamper protection blocks to disable key Microsoft Defender Antivirus and real-time protection settings.
Bhabesh Raj, Nasreddine Bencherchali, Huntrule TeamWindowswindefendHigh211Free2021-07-05