Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,079 rules
Windows Service Control Manager: WerFaultSvc Installed via Service Creation (Event ID 7045)
Alerts on Windows Event 7045 service creation for "WerFaultSvc" as an indicator of dropper-style persistence.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemCritical373Free2018-11-23Windows: Suspicious Executable Downloads Missing File Metadata Fields
Alerts when a process launches from Downloads with missing/placeholder file metadata (Description, FileVersion, Product, or Company).
Markus Neis, Sander Wiebing, Huntrule TeamWindowsprocess_creationMedium121Free2018-11-22Windows Process Creation—CommandLine Indicators for APT29 2018 Phishing Campaign
Alerts on Windows command-line substrings seen in the 2018 APT29 phishing campaign indicators.
Florian Roth (Nextron Systems), @41thexplorer, Huntrule TeamWindowsprocess_creationCritical83Free2018-11-20Windows File Events: Detect ds7002*.lnk, .pdf, and .zip Indicators
Flags Windows file events with target filenames containing ds7002.lnk, ds7002.pdf, or ds7002.zip.
"@41thexplorer, Huntrule Team"Windowsfile_eventCritical101Free2018-11-20Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Flags PowerShell script blocks containing Base64 strings matching known shellcode markers.
David Ledbetter (shellcode), Florian Roth (Nextron Systems), Huntrule TeamWindowsps_scriptHigh113Free2018-11-17Windows: Potential Kerberoasting SPN Enumeration via setspn.exe
Detects Windows setspn.exe runs with SPN query command-line parameters that may indicate Kerberoasting preparation.
Markus Neis, keepwatch, Huntrule TeamWindowsprocess_creationMedium405Free2018-11-14Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh152Free2018-10-30Windows: Local user account creation via net.exe or net1.exe
Alerts on net.exe/net1.exe launching with "user" and "add" to create local accounts on Windows.
Endgame, JHasenbusch (adapted to Sigma for oscd.community), Huntrule TeamWindowsprocess_creationMedium40Free2018-10-30Antivirus Web Shell Signature Matches Across ASP, JSP, PHP, Perl, and VBS
Alerts on AV signatures indicating web shells/backdoors (ASP/JSP/PHP/Perl/VBS/Webshell) to support fast investigation of persistence.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusHigh248Free2018-09-09Antivirus alerts for suspicious file paths and web/script file extensions
Alerts on AV hits involving suspicious file locations and web/script-related extensions.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusHigh82Free2018-09-09Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Triggers on AV signatures matching PWS* or known credential-dumping tool strings indicating potential password theft activity.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical93Free2018-09-09Antivirus signature match for exploitation framework indicators
Alerts when AV signature names contain indicators tied to exploitation frameworks and related backdoors.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule Team—antivirusCritical201Free2018-09-09Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Flags PowerShell (powershell.exe/pwsh) process executions with command-line indicators consistent with XOR/obfuscated scripting.
Sami Ruohonen, Harish Segar, Tim Shelton, Teymur Kheirkhabarov, Vasiliy Burov, oscd.community, Nasreddine Bencherchali, Huntrule TeamWindowsprocess_creationMedium247Free2018-09-05Windows PowerShell Suspicious Encoded Command-Line Execution
Alerts on PowerShell launched with encoded-command switches and embedded encoded content patterns in the command line.
Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, Anton Kutepov, oscd.community, Huntrule TeamWindowsprocess_creationHigh238Free2018-09-03Windows process creation: svchost.exe launched by sllauncher.exe for DLL side-loading
Flags AppData\Roaming-launched svchost.exe instances spawned by sllauncher.exe with -k, matching DLL side-loading execution behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical113Free2018-09-03