Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,084 rules
Windows ETW Trace Evasion via Clearing/Disabling Logs or Providers
Identifies command-line attempts to clear/disable ETW traces or remove/modify ETW providers on Windows.
"@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule Team"Windowsprocess_creationHigh112Free2019-03-22Qualys: Alert When Firewall Product Is Not Detected on a Host
Alerts when Qualys reports a host missing a detectable firewall product during vulnerability management scanning.
Alexandr Yampolskyi, SOC Prime, Huntrule TeamQualys—Low50Free2019-03-19Microsoft BITS Proxy Activity to Uncommon Top-Level Domains
Flags Microsoft BITS-initiated proxy requests to domains using uncommon TLDs.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWebproxyHigh209Free2019-03-07Windows Process CommandLine contains -export dll_u (DLL export function load)
Flags Windows processes that invoke a DLL export function named dll_u via command-line export arguments.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical188Free2019-03-04Windows Security: ScheduledDefrag Task Deactivated via Event ID 4701
Flags Windows EventID 4701 activity that disables the ScheduledDefrag scheduled task.
Florian Roth (Nextron Systems), Bartlomiej Czyz (@bczyz1), Huntrule TeamWindowssecurityMedium395Free2019-03-04Windows ScheduledDefrag task removal via schtasks /delete and /change
Detects schtasks.exe commands that delete or change the ScheduledDefrag scheduled task.
Florian Roth (Nextron Systems), Bartlomiej Czyz (@bczyz1), Huntrule TeamWindowsprocess_creationMedium336Free2019-03-04Windows: certutil.exe File Encoding to Base64 Using the -encode Flag
Alerts on Windows certutil.exe executions using -encode to base64-encode a file.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium60Free2019-02-24Windows: PowerShell-triggered HTA retrieval and execution with registry and process disruption
Alerts on Windows process creation where PowerShell uses mshta over HTTP and includes .hta, registry query, and cmd.exe termination.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh411Free2019-02-24Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
vburov, Huntrule TeamWindowsprocess_creationLow142Free2019-02-23Windows mshta.exe Execution Using Non-HTA File Extensions
Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.
Diego Perez (@darkquassar), Markus Neis, Swisscom (Improve Rule), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh101Free2019-02-22Windows: RDP Session Startup Folder Backdoor via tsclient Share Targeting Startup Path
Flags mstsc.exe activity writing to the Windows Startup folder, indicating potential RDP session backdoor placement.
Samir Bousseaden, Huntrule TeamWindowsfile_eventHigh143Free2019-02-21Windows svchost RDP via Reverse SSH Loopback Tunnel to 127.0.0.0/8:3389
Flags svchost.exe opening RDP (TCP 3389) connections to loopback, consistent with tunneled reverse access behavior.
Samir Bousseaden, Huntrule TeamWindowsnetwork_connectionHigh2010Free2019-02-16Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh103Free2019-02-16Windows Registry Persistence Attempt Using AppDataLow Ursnif-Related Path
Alerts on Windows registry key additions matching a Ursnif-associated TargetObject path.
megan201296, Huntrule TeamWindowsregistry_addHigh132Free2019-02-13Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh464Free2019-02-11