Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
6,760 rules
Windows Java Process Started with Remote Debugging Enabled for Non-Localhost Connections
Identifies Java processes started with JDWP dt_socket remote debugging on a non-localhost address.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium344Free2019-01-16Windows Cmdkey.EXE Cached Credential Reconnaissance
Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.
jmallette, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2019-01-16Windows cmd.exe Command Line with URL and %AppData% Indicators
Alerts on cmd.exe executions whose command line includes a URL pattern (http/https) and %AppData%.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium60Free2019-01-16Windows Script File Execution via Wscript/Cscript Using Script File Extensions
Flags wscript.exe or cscript.exe executing common script file types via command-line extensions on Windows.
Michael Haag, Huntrule TeamWindowsprocess_creationMedium50Free2019-01-16Windows: Process execution from web server root folders (wwwroot, htdocs, wmpub)
Alerts on Windows processes executing from typical web server root folders, consistent with webshell or backdoor staging.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium120Free2019-01-16Windows Process Creation: Execution of Net.exe or Net1.exe
Alerts on execution of net.exe/net1.exe with common net subcommands via Windows process creation and command-line telemetry.
Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements), Huntrule TeamWindowsprocess_creationLow60Free2019-01-16Windows Execution of Microsoft.Workflow.Compiler.exe
Flags Windows process executions of Microsoft.Workflow.Compiler.exe, a binary that may be abused for arbitrary unsigned code execution.
Nik Seetharaman, frack113, Huntrule TeamWindowsprocess_creationMedium50Free2019-01-16Windows process activity matching WannaCry executables and ransom note text
Alerts on Windows process creation where WannaCry-related executables and the @Please_Read_Me@.txt command indicator appear.
Florian Roth (Nextron Systems), Tom U. @c_APT_ure (collection), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationCritical428Free2019-01-16Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution
Flags Windows process execution indicative of NotPetya: clearing event logs with wevtutil and deleting C drive USN journal with fsutil.
Florian Roth (Nextron Systems), Tom Ueltschi, Huntrule TeamWindowsprocess_creationCritical123Free2019-01-16Windows WMI Event Subscription Creation (Sysmon Event 19/20/21)
Flags Sysmon-reported WMI event subscription filter/consumer activity (Event IDs 19–21) indicative of persistence.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowswmi_eventMedium91Free2019-01-12Windows Registry Persistence via UserInitMprLogonScript Value
Detects registry value name containing "UserInitMprLogonScript", which may indicate logon-script persistence setup.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowsregistry_setMedium132Free2019-01-12Windows userinit.exe Spawns Uncommon Child Processes
Alerts when userinit.exe starts an unexpected child process during logon, suggesting potential persistence via modified logon behavior.
Tom Ueltschi (@c_APT_ure), Tim Shelton, Huntrule TeamWindowsprocess_creationHigh429Free2019-01-12Windows Command Line Logon Script Persistence via UserInitMprLogonScript
Alerts when a Windows process command line references UserInitMprLogonScript, a potential logon-script persistence indicator.
Tom Ueltschi (@c_APT_ure), Huntrule TeamWindowsprocess_creationHigh203Free2019-01-12Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools
Alerts on suspicious svchost.exe or regsvr32.exe process executions with matching command-line and parent/child patterns indicative of Dridex activity.
Florian Roth (Nextron Systems), oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical368Free2019-01-10PowerShell Executed From AppData on Windows (Command Line Indicators)
Flags PowerShell command lines that include AppData paths (Local/Roaming), indicating possible user-profile script execution.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium112Free2019-01-09