Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,138 rules
Xwizard.EXE COM Execution with RunWizard and GUID Argument (Windows)
Alerts when Xwizard.EXE runs with RunWizard plus a GUID-like argument on Windows, consistent with COM execution usage.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium244Free2020-10-07Windows: Remote code execution via winrm.vbs using cscript and wmicimv2/Win32_ Create
Alerts on cscript.exe executions referencing winrm and wmicimv2/Win32_ Create with -r:http, consistent with remote code execution via winrm.vbs.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium136Free2020-10-07Rundll32 Executes Setupapi.dll InstallHinfSection via Runonce.exe
Alerts when rundll32 passes setupapi.dll::InstallHinfSection arguments that result in launching runonce.exe.
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium325Free2020-10-07Windows DLL execution via register-cimprovider.exe with -path dll
Alerts on register-cimprovider.exe launching with -path pointing to a DLL.
Ivan Dyachkov, Yulia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium81Free2020-10-07Windows regedit.exe Imports Registry Keys From .reg File
Detects regedit.exe command lines importing registry keys from .reg files on Windows.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationMedium50Free2020-10-07Windows Registry Key Export via regedit.exe (-E) to File
Flags regedit.exe registry exports to files using the -E option, indicating potential discovery or exfiltration prep.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow123Free2020-10-07Windows Visual Basic vbc.exe Compiles to .obj via cvtres.exe Resource Converter
Alerts when vbc.exe spawns cvtres.exe during Windows VB command-line compilation activity.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Huntrule TeamWindowsprocess_creationHigh111Free2020-10-07Windows: Process CallTrace using EditionUpgradeManager COM interface DLL
Alerts on process access events with call traces referencing editionupgrademanagerobj.dll via the EditionUpgradeManager COM interface.
oscd.community, Dmitry Uchakin, Huntrule TeamWindowsprocess_accessMedium112Free2020-10-07Windows regedit.exe exports a registry key into an alternate data stream
Flags regedit.exe executions where the process image ends with '\regedit.exe', consistent with exporting Registry data to an alternate data stream.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowscreate_stream_hashHigh123Free2020-10-07Linux Process Creation: File Deletion via rm, shred, or unlink
Alerts on Linux process executions of rm, shred, or unlink used to delete files.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationInformational90Free2020-10-07Linux process attempts to delete log files using rm, rmdir, shred, or unlink
Flags Linux attempts to remove or destroy log files via rm/rmdir/shred/unlink when /var/log or mail spool paths are referenced.
Ömer Günal, oscd.community, Huntrule TeamLinuxprocess_creationMedium80Free2020-10-07Windows Diskshadow Script Mode Execution via /s Flag
Alerts when Diskshadow is executed in script mode using the /s flag.
Ivan Dyachkov, oscd.community, Huntrule TeamWindowsprocess_creationMedium60Free2020-10-07PowerShell Service Persistence via Registry ImagePath on Windows
Flags Windows registry service ImagePath entries that reference PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh172Free2020-10-06Windows: Winrm.vbs AWL bypass using attacker WsmPty.xsl/WsmTxt.xsl
Detects WinRM vbs execution with suspicious XSL formatting arguments, especially when the binary is outside System32/SysWOW64.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium354Free2020-10-06Windows: VBoxDrvInst.exe Invoked with driver/executeinf Parameters
Flags VBoxDrvInst.exe launched with parameters indicative of INF processing (driver/executeinf).
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium141Free2020-10-06