Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,116 rules
Windows Process Command Lines Using System32/SysWow64 Tasks Folder
Alerts on process command lines referencing the writable System32/SysWow64 Tasks folders with common file staging/copy primitives.
Sreeman, Huntrule TeamWindowsprocess_creationHigh63Free2020-01-13Windows Process: curl Download with HTTP Output Redirect and Command Chaining
Flags Windows commands where curl downloads over HTTP with -o and then executes via command chaining with '&'.
Sreeman, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh40Free2020-01-13Windows: Koadic Command Prompt Invocation with /q /c chcp
Flags cmd.exe executions with /q /c and chcp in the command line, matching Koadic-style command parameters.
wagga, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh421Free2020-01-12Windows Process Access to svchost.exe with High-Rights GrantedAccess
Alerts on high-privilege access to svchost.exe when process call context is UNKNOWN, excluding MSBuild-origin traffic.
Tim Burrell, Huntrule TeamWindowsprocess_accessHigh157Free2020-01-02Citrix NetScaler CVE-2019-19781 Attempted Exploitation via Web Requests
Flags suspicious NetScaler HTTP URIs containing traversal-style /vpns/ portal script or config file references.
Arnim Rupp, Florian Roth, Huntrule Team—webserverCritical236Free2020-01-02Windows Registry Access to WCESERVICE Start Key
Detects registry activity targeting the WCE service Start configuration in Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_eventCritical252Free2019-12-31Windows Process Execution of Windows Credential Editor (WCE) Executables
Flags execution of Windows Credential Editor (WCE.exe/WCE64.exe) using image name endings and known imphash values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical285Free2019-12-31Windows Process Creation: svchost.exe Spawned Without Command-Line Arguments
Flags svchost.exe process starts lacking command-line values, excluding rpcnet/rpcnetp parent cases.
David Burkett, @signalblur, Huntrule TeamWindowsprocess_creationHigh111Free2019-12-28Windows CreateMiniDump.exe HackTool Execution via Process Creation
Detects the execution of CreateMiniDump.exe using image name and a specific IMPHASH.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2019-12-22Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Alerts on SharpHound/Bloodhound-like processes launching with discovery-focused command-line parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh124Free2019-12-20Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)
Detects Windows Security Event 4799 where checkadmin.exe targets “Administr*” accounts, consistent with admin account enumeration.
Florian Roth (Nextron Systems), frack113, Huntrule TeamWindowssecurityHigh406Free2019-12-20Ursnif dropper download URLs matching PHP l= parameter ending in CAB
Flags proxy responses where a request URI contains /.php?l= and ends with .cab, returning HTTP 200.
Thomas Patzke, Huntrule Team—proxyHigh3110Free2019-12-19Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Flags proxy requests with Base64-like URI characters plus '/images/' and '.avi' patterns consistent with Ursnif C2.
Thomas Patzke, Huntrule Team—proxyCritical51Free2019-12-19Windows Process Execution Indicative of Ryuk-Style Ransomware Behavior
Flags suspicious Windows process command lines combining autorun persistence, public staging, file backup wiping, and service stoppage behavior.
Florian Roth (Nextron Systems), Vasiliy Burov, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh363Free2019-12-16Windows Process Creation: IIS appcmd Native Module Installation via Command Line
Alerts on appcmd.exe commands installing IIS native-code modules using a -name: parameter, excluding iissetup-launched setups.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium92Free2019-12-11