Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,087 rules
Windows Process Creation: Suspicious Renamed Binary Masquerading as Common Tools
Flags Windows executions where Sysmon OriginalFileName matches common tools but the process Image name ends differently.
Matthew Green @mgreen27, Ecco, James Pemberton @4A616D6573, oscd.community, Andreas Hunkeler (@Karneades), Huntrule TeamWindowsprocess_creationMedium149Free2019-06-15Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Flags Windows 4624 successful logons consistent with Pass-the-Hash activity using NtLmSsp or seclogo.
Dave Kennedy, Jeff Warren (method) / David Vassallo (rule), Huntrule TeamWindowssecurityMedium30Free2019-06-14Webserver URL Enumeration for Exposed .git Paths via GET Keyword
Alerts when web requests include .git/ in the URL, suggesting source code enumeration against version control paths.
James Ahearn, Huntrule TeamWebwebserverMedium102Free2019-06-08Windows Process Creation: Renamed jusched.exe Execution via Java Scheduler Names
Alerts when Java Update Scheduler descriptions are used to execute a process ending with \jusched.exe on Windows.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh238Free2019-06-04Windows Security 4625 Logon Failures to TargetUserName AAAAAAA Indicative of RDP Scan PoC
Alerts on Windows failed logon (4625) events matching a BlueKeep scanner PoC TargetUserName value.
Florian Roth (Nextron Systems), Adam Bradbury (idea), Huntrule TeamWindowssecurityHigh152Free2019-06-02Windows System Log RDP TermDD Errors Matching EventIDs 50 or 56
Flags suspicious TermDD RDP error events (Event IDs 50/56) on Windows that may indicate CVE-2019-0708 activity.
Lionel PRAT, Christophe BROCAS, @atc_project (improvements), Huntrule TeamWindowssystemMedium81Free2019-05-24Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh395Free2019-05-22Potential BearLPE Exploitation via Windows Task Scheduler schtasks.exe DACL Change
Flags schtasks.exe executions with /change, /TN, /RU, and /RP, consistent with task modification tied to BearLPE attempts.
Olaf Hartong, Huntrule TeamWindowsprocess_creationHigh142Free2019-05-22WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
Patryk Prauze - ING Tech, Huntrule TeamWindowsprocess_accessHigh239Free2019-05-20Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
Alec Costello, Huntrule TeamWindowsps_scriptHigh248Free2019-05-16Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.
Markus Neis, Huntrule TeamWindowsnetwork_connectionHigh71Free2019-05-15Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh127Free2019-04-20Windows Local User Creation (Security Event 4720)
Flags Windows Security Event ID 4720 indicating a local user account was created.
Patrick Bareiss, Huntrule TeamWindowssecurityLow3210Free2019-04-18Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowswmi_eventHigh113Free2019-04-15Windows Registry: Create/Modify CLSID/AppX keys associated with OceanLotus decoy paths
OceanLotus Registry Activity
megan201296, Jonhnathan Ribeiro, Huntrule TeamWindowsregistry_eventCritical121Free2019-04-14