Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,079 rules
Windows Execution of Microsoft.Workflow.Compiler.exe
Flags Windows process executions of Microsoft.Workflow.Compiler.exe, a binary that may be abused for arbitrary unsigned code execution.
Nik Seetharaman, frack113, Huntrule TeamWindowsprocess_creationMedium20Free2019-01-16Windows process activity matching WannaCry executables and ransom note text
Alerts on Windows process creation where WannaCry-related executables and the @Please_Read_Me@.txt command indicator appear.
Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationCritical428Free2019-01-16Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution
Flags Windows process execution indicative of NotPetya: clearing event logs with wevtutil and deleting C drive USN journal with fsutil.
Florian Roth (Nextron Systems), Tom Ueltschi, Huntrule TeamWindowsprocess_creationCritical113Free2019-01-16Windows WMI Event Subscription Creation (Sysmon Event 19/20/21)
Flags Sysmon-reported WMI event subscription filter/consumer activity (Event IDs 19–21) indicative of persistence.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowswmi_eventMedium61Free2019-01-12Windows Registry Persistence via UserInitMprLogonScript Value
Detects registry value name containing "UserInitMprLogonScript", which may indicate logon-script persistence setup.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowsregistry_setMedium72Free2019-01-12Windows userinit.exe Spawns Uncommon Child Processes
Alerts when userinit.exe starts an unexpected child process during logon, suggesting potential persistence via modified logon behavior.
Tom Ueltschi (@c_APT_ure), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh399Free2019-01-12Windows Command Line Logon Script Persistence via UserInitMprLogonScript
Alerts when a Windows process command line references UserInitMprLogonScript, a potential logon-script persistence indicator.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowsprocess_creationHigh173Free2019-01-12Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools
Alerts on suspicious svchost.exe or regsvr32.exe process executions with matching command-line and parent/child patterns indicative of Dridex activity.
Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical368Free2019-01-10PowerShell Executed From AppData on Windows (Command Line Indicators)
Flags PowerShell command lines that include AppData paths (Local/Roaming), indicating possible user-profile script execution.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium82Free2019-01-09Windows Process Creation: Outlook EnableUnsafeClientMailRules Security Setting Enabled
Flags Windows process command lines that reference Outlook’s EnableUnsafeClientMailRules security setting.
Markus Neis, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2018-12-27Windows Process Creation: SecurityXploded PasswordDump.exe Execution
Alerts on Windows executions of SecurityXploded PasswordDump.exe based on process metadata and filename.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical382Free2018-12-19Windows Process Creation: Rubeus HackTool Execution Indicators
Flags Windows process executions of Rubeus.exe when command lines include Kerberos attack-related actions.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical146Free2018-12-19Windows Process Creation: Command Line Obfuscation via Escape Characters
Identifies Windows process command lines containing escape-character URL obfuscation patterns.
juju4, Huntrule TeamWindowsprocess_creationMedium102Free2018-12-11Windows Remote Thread Injection Indicators via Process StartAddress Suffixes
Flags Windows CreateRemoteThread events with StartAddress suffixes 0B80, 0C7C, or 0C88.
Olaf Hartong, Florian Roth (Nextron Systems), Aleksey Potapov, oscd.community, Huntrule TeamWindowscreate_remote_threadHigh355Free2018-11-30Zeek SMB spoolss Named Pipe (IPC$) Access
Flags Zeek SMB events accessing the spoolss named pipe via IPC$.
OTR (Open Threat Research), @neu5ron, Huntrule TeamZeeksmb_filesMedium298Free2018-11-28