Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
3,607 rules
Windows Process Creation: UAC bypass attempt via MMC Windows Firewall Snap-in hijack
Alerts when MMC launches WF.msc, a possible UAC bypass snap-in hijack pattern, excluding WerFault.exe-related cases.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium2910Free2022-09-27Windows Process Creation: SSH Port-Forwarding Commands Targeting RDP (3389)
Flags Windows command lines using SSH port-forwarding switches that also reference RDP port :3389.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium111Free2022-09-27Windows ImagingDevices.exe Spawns Unusual Parent/Child Processes
Alerts when ImagingDevices.exe participates in atypical process parent/child chains on Windows, based on process creation telemetry.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh273Free2022-09-27Windows: Unusual Child Process Spawn by dns.exe
Alerts when dns.exe launches an unexpected child process other than conhost.exe.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationHigh151Free2022-09-27Windows desktopimgdownldr.exe Remote File Download via /lockscreenurl:http
Flags desktopimgdownldr.exe executions that specify a remote lockscreen URL via /lockscreenurl:http.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium142Free2022-09-27Windows Process Creation: 7-Zip Compressing .dmp/.dump Files
Flags Windows executions of 7-Zip where the command line includes .dmp/.dump/.hdmp extensions.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2610Free2022-09-27Windows dns.exe Deletes Files with Unexpected Targets
Alerts when dns.exe deletes any file other than dns.log on Windows.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_deleteHigh82Free2022-09-27Windows: Unusual File Modification by dns.exe
Alert on dns.exe changing files other than dns.log, which can indicate suspicious or compromised system activity.
Tim Rauch (Nextron Systems), Elastic (idea), Huntrule TeamWindowsfile_changeHigh423Free2022-09-27Windows Remote Thread Creation via rundll32 Triggered by wab*, wabmig, or ImagingDevices
Alerts on remote thread creation targeting rundll32.exe from wab* or ImagingDevices.exe process images on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowscreate_remote_threadHigh236Free2022-09-27PowerShell Script Exfiltration Attempt: Send-MailMessage with Attachments
Detects PowerShell Send-MailMessage usage with -Attachments, which may indicate SMTP-based data exfiltration.
frack113, Huntrule TeamWindowsps_scriptMedium60Free2022-09-26Windows: w32tm.exe Timer/Delay Usage via stripchart Parameters
Flags w32tm.exe executions using stripchart delay-related parameters that can support timed automation on Windows.
frack113, Huntrule TeamWindowsprocess_creationHigh462Free2022-09-25Windows UltraViewer Desktop App Execution
Alerts on execution of UltraViewer Desktop on Windows based on executable metadata in process creation events.
frack113, Huntrule TeamWindowsprocess_creationMedium4210Free2022-09-25Windows Process Creation: NetSupport Client Configurator (PCICFGUI.EXE)
Alerts on execution of NetSupport Client Configurator (PCICFGUI.EXE) on Windows via process metadata.
frack113, Huntrule TeamWindowsprocess_creationMedium133Free2022-09-25Windows: Suspicious Parent Process Spawning cmd.exe
Alerts on cmd.exe executions that have a suspicious/atypical parent process among listed Windows binaries.
Tim Rauch, Elastic (idea), Huntrule TeamWindowsprocess_creationMedium264Free2022-09-21Windows Process Creation: Renamed createdump.exe Used for .dmp Memory Dumps
Flags renamed createdump.exe executions on Windows that use full dump flags and produce .dmp files.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh93Free2022-09-20