Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,069 rules
Windows Process Creation with taskmgr.exe as Parent Process
Flags process creation where taskmgr.exe is the parent, excluding a few known benign child process images.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow62Free2018-03-13Windows WMI Script Event Consumer Execution via scrcons.exe
Flags scrcons.exe starting under svchost.exe, indicating WMI script event consumer execution that can support persistence.
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium217Free2018-03-07Windows WMI Persistence via wbemcons.dll Loaded by WmiPrvSE.exe
Identifies WmiPrvSE.exe loading wbemcons.dll, a behavior consistent with WMI command line event consumer persistence on Windows.
Thomas Patzke, Huntrule TeamWindowsimage_loadHigh63Free2018-03-07Windows WMI Persistence: Script Event Consumer File Writes (scrcons.exe)
Flags file writes performed by scrcons.exe, indicating potential WMI script event consumer persistence activity.
Thomas Patzke, Huntrule TeamWindowsfile_eventHigh429Free2018-03-07Windows Scheduled Task Creation via PowerShell Using schtasks.exe with ONLOGON/DAILY/ONIDLE/HOURLY
Flags PowerShell-launched schtasks.exe /Create commands matching default PowerSploit/Empire scheduled task persistence behavior.
Markus Neis, @Karneades, Huntrule TeamWindowsprocess_creationHigh231Free2018-03-06Windows rundll32 Trojan Loader Execution via Local AppData and .dat Parameters
Flags rundll32.exe launched with AppData/local .dat and .dll patterns consistent with Trojan loader behavior.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh102Free2018-03-01Windows process creation: Winword launching FLTLDR.exe exploitation behavior
Alerts when Winword spawns a FLTLDR.exe child process, matching a CVE-2017-0261-style exploit chain.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium63Free2018-02-22WinWord spawning MicroScMgmt.exe indicative of CVE-2015-1641 exploitation on Windows
Alerts when Winword.exe starts MicroScMgmt.exe, matching a known CVE-2015-1641 exploitation behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical141Free2018-02-22Linux syslog: Detect suspicious BIND/named error messages
Alerts on Linux syslog messages with BIND named fatal or denied DNS error strings.
Florian Roth (Nextron Systems), Huntrule TeamLinuxsyslogHigh92Free2018-02-20Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.
Roberto Rodriguez (source), Dominik Schaudel (rule), Huntrule TeamWindowssecurityHigh80Free2018-02-12Windows File Creation: QuarksPwDump Credential Dump (.dmp) in Temp\SAM-*
Flags creation of QuarksPwDump .dmp dump files in Temp with a SAM-* filename pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventCritical313Free2018-02-10Windows msiexec Process Creation With Web URL Parameters
Alerts when msiexec is launched with command-line web URL indicators in its parameters.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium111Free2018-02-09Windows Process Creation: svchost Running NavShExt.dll Deletion/Setting Commands
Alerts on svchost.exe process commands referencing cached NavShExt.dll deletion and execution markers consistent with Elise backdoor activity.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical386Free2018-01-31Linux Auditd: Program Executions from Suspicious Web and Data Directories
Alerts on Linux process creation when the executed binary path begins with commonly abused temp/web/data directories.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdMedium83Free2018-01-23Linux auditd: Executing suspicious chmod and cp commands
Triggers on auditd EXECVE events for chmod (777/u+s) and cp overwriting /bin/ksh or /bin/sh.
Florian Roth (Nextron Systems), Huntrule TeamLinuxauditdMedium51Free2017-12-12