Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,760 rules
Windows Process Creation Attempt Using wmic.exe process call create
Alerts on Windows process creation attempts invoking wmic.exe with “process call create”, a common pattern for WMI-based execution.
Michael Haag, Florian Roth (Nextron Systems), juju4, oscd.community, Huntrule TeamWindowsprocess_creationMedium60Free2019-01-16Windows Suspicious Child Processes Spawned by Web Server Executables
Alerts when web server processes (e.g., nginx/httpd/caddy/php/tomcat) spawn suspicious Windows command/scripting executables.
Thomas Patzke, Florian Roth (Nextron Systems), Zach Stanford @svch0st, Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh183Free2019-01-16Windows Process Execution From Uncommon or Sensitive Directories
Alerts on process executions from uncommon/sensitive Windows directories, excluding specific IBM and Citrix updater paths.
Florian Roth (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh162Free2019-01-16Windows Shim Database Persistence via sdbinst.exe with .sdb Payload
Alerts when sdbinst.exe runs and references a .sdb shim database, indicating potential shim-based persistence.
Markus Neis, Huntrule TeamWindowsprocess_creationMedium73Free2019-01-16Windows schtasks.exe Scheduled Task Creation by Non-Microsoft Office Integration
Alerts on schtasks.exe /create executions indicating scheduled task creation, with exclusions for Office integrator-related cases.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationLow247Free2019-01-16Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
juju4, Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium205Free2019-01-16Windows Process Execution from Unusual System Locations
Alerts on Windows process launches where the executable path is in or contains unusual directories like RECYCLER or SystemVolumeInformation.
juju4, Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium394Free2019-01-16Windows Suspicious rasdial.exe Process Execution
Flags Windows process executions of rasdial.exe by matching process image names ending with rasdial.exe.
juju4, Huntrule TeamWindowsprocess_creationMedium245Free2019-01-16Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix), Huntrule TeamWindowsprocess_creationHigh336Free2019-01-16PowerShell Spawned by wscript.exe or cscript.exe on Windows
Flags PowerShell launched by Windows script engines (wscript/cscript), excluding specific Health Service State activity.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium149Free2019-01-16Windows PowerShell execution with download-related command line patterns
Alerts when PowerShell is started with command-line fragments indicative of downloading remote content.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationMedium142Free2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
John Lambert (rule), Huntrule TeamWindowsprocess_creationHigh121Free2019-01-16Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
Thomas Patzke, Huntrule TeamWindowsprocess_creationMedium265Free2019-01-16Windows Process Reconnaissance via net.exe Group/Account Queries
Alerts on Windows net.exe commands querying groups and accounts via domain/local group and /do-related flags.
Florian Roth (Nextron Systems), omkar72, @svch0st, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium151Free2019-01-16Windows Process Creation: Suspicious Children Spawned by mshta.exe
Flags mshta.exe spawning command, script, or utility processes commonly abused for executing malicious HTA payloads.
Michael Haag, Huntrule TeamWindowsprocess_creationHigh503Free2019-01-16