Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,161 rules
Windows Process Creation: Detect ShimCache Flush via rundll32 apphelp.dll/kernel32.dll
Flags rundll32 command-line activity that flushes ShimCache via apphelp.dll or kernel32.dll entry points.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2021-02-01Windows rundll32.exe execution with no parameters or arguments
Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowsprocess_creationHigh111Free2021-01-31Windows WMIC Uninstall/Terminate Actions Targeting Security Products
Flags WMIC commands on Windows that attempt to uninstall or terminate security products or sensors using known vendor/product strings.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2021-01-30Windows Command-Line Disables Volume Shadow Copy (VSS) Snapshots
Flags Windows command lines that disable Volume Shadow Copy (VSS) snapshots via VSS Diag service switches.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2021-01-28Webserver Detection: SonicWall SSL VPN Jarrewrite Exploitation URI and User-Agent Payloads
Flags web requests to /cgi-bin/jarrewrite.sh with user-agent indicators consistent with command injection exploitation.
Florian Roth (Nextron Systems), Huntrule Team—webserverHigh417Free2021-01-25Webserver detection of TerraMaster TOS CVE-2020-28188 exploit requests
Flags GET requests to /include/makecvs.php with Event plus indicators of script download/execute behavior tied to CVE-2020-28188.
Bhabesh Raj, Huntrule Team—webserverHigh165Free2021-01-25Windows Security: Detect Scheduled Task Deletion (EventID 4699)
Flags Windows scheduled task deletions from Security EventID 4699 while excluding common MRT and Firefox-related tasks.
David Strassegger, Tim Shelton, Huntrule TeamWindowssecurityLow70Free2021-01-22Windows Process Creation: 7z Archive Creation with Script/Command Launch Chaining
Flags Windows process creation chaining 7z archive commands with .zip plus .txt/.log extensions and wscript+rundll32 context.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh92Free2021-01-22Windows Process Creation: Raccine Removal via taskkill, registry and scheduled task deletion
Detects command-line activity that stops and removes Raccine components through process killing, registry deletion, and scheduled task removal.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2021-01-21Windows Service Installation (EID 4697) for SMB PsExec by Metasploit or Impacket
Alerts on Windows Event ID 4697 service installs matching SYSTEMROOT\8char.exe and on-demand start, consistent with PsExec-style SMB execution.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowssecurityHigh163Free2021-01-21Web server requests targeting WebLogic JNDI LDAP via JndiBindingHandle (CVE-2021-2109)
Alerts on GET requests with WebLogic JndiBindingHandle and an ldap:// payload targeting AdminServer.
Bhabesh Raj, Huntrule Team—webserverCritical409Free2021-01-20Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Flags Windows command lines where PowerShell/WMI is used to spawn rundll32 from c:\windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical143Free2021-01-20Windows Plink Remote Port Forwarding via -R Command Line
Alerts on Windows process command lines using Plink " -R " remote port forwarding to a local port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh406Free2021-01-19Windows System Log: NTFS File System Driver Event 55 Indicates Possible NTFS Exploitation
Alerts on Windows NTFS Event ID 55 indicating a corrupted file record with a matching filename string in the event description.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh312Free2021-01-11Windows Registry Persistence via VSTO Add-ins in Microsoft Office
Flags registry writes that register VSTO/Office add-ins for Outlook, Word, Excel, or PowerPoint persistence on Windows.
Bhabesh Raj, Huntrule TeamWindowsregistry_setMedium133Free2021-01-10