Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,094 rules
Windows Registry: Suspicious Keyboard Layout Preload in User Session
Detects user-hive registry changes that preload Persian (Iranian) or Vietnamese keyboard layouts under Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsregistry_setMedium312Free2019-10-12Windows Screen Capture via psr.exe (Problem Steps Recorder) Execution
Flags psr.exe launched with /start or -start, indicating potential user screen and click recording.
Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationMedium63Free2019-10-12Windows OpenWith.exe Launches Another Binary via /c
Flags Windows OpenWith.exe executions that include '/c', indicating it launched another binary.
Beyu Denis, oscd.community (rule), @harr0ey (idea), Huntrule TeamWindowsprocess_creationHigh42Free2019-10-12Windows Devtoolslauncher.exe LaunchForDeploy Executes a Specified Binary
Alerts when devtoolslauncher.exe runs with LaunchForDeploy, indicating it may launch another binary on Windows.
Beyu Denis, oscd.community (rule), @_felamos (idea), Huntrule TeamWindowsprocess_creationHigh337Free2019-10-12Linux auditd: Webshell Remote Command Execution via execve/execveat (euid=33)
Alerts on execve/execveat executions by the web server user, consistent with potential webshell command execution.
Ilyas Ochkov, Beyu Denis, oscd.community, Huntrule TeamLinuxauditdCritical122Free2019-10-12Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical111Free2019-10-11PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh60Free2019-10-08PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh277Free2019-10-08Windows regsvr32 DLLLoad from AppData Local containing DllEntry
Alerts when regsvr32 loads a DLL from AppData\Local with a DllEntry reference.
Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2019-10-02Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders
Alerts on registry Run key writes originating from Downloads or temporary Outlook/IE directories on Windows.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poude (Nextron Systems), Huntrule TeamWindowsregistry_eventHigh93Free2019-10-01Suspicious Windows Program Execution from Outlook Temporary Internet Files Folder
Alerts on process executions whose image path points to Outlook temporary files (Content.Outlook).
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh122Free2019-10-01Windows Process Activity Indicative of QBot (WinRAR to wscript, ping/type, regsvr32)
Alerts on Windows process creation consistent with QBot-like script execution chains from WinRAR and regsvr32/tmp staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical291Free2019-10-01Windows Formbook-style process execution deleting dropped payloads from AppData Temp via cmd
Flags Windows process creation where an .exe runs deletion commands to remove dropper artifacts from AppData Temp/Desktop.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh123Free2019-09-30Windows Process Creation: Emotet-like Command-Line Patterns
Alerts on Windows process executions with command-line indicators consistent with Emotet-like staging and encoded payload usage.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh81Free2019-09-30Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh123Free2019-09-26