Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
94 rules
Windows Process Creation Indicators for Snatch Ransomware Word Document Droppers
Alerts on Windows process command lines showing instant safe-mode shutdown/reboot and stopping SuperBackupMan service.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh111Free2020-08-26Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical169Free2020-05-08Windows Process Execution Indicative of Ryuk-Style Ransomware Behavior
Flags suspicious Windows process command lines combining autorun persistence, public staging, file backup wiping, and service stoppage behavior.
Florian Roth (Nextron Systems), Vasiliy Burov, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh373Free2019-12-16Windows Application Logs: Match Antivirus Signature and Malware Keyword Hits
Alerts on Windows application log lines containing known AV signatures and malware keywords, excluding some anti-ransomware/keygen/crack terms.
Florian Roth (Nextron Systems), Arnim Rupp, Huntrule TeamWindowsapplicationHigh63Free2017-02-19