Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
PowerShell Classic Compress-Archive staging in TEMP or Temp directories
Alerts on PowerShell Compress-Archive output targeting common Temp directories for data staging.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowspowershell-classicMedium5410Free2021-07-20Windows mshta.exe Process Creation Triggered by Suspicious Command Lines
Alert on mshta.exe launches from suspicious parents and script-like command lines/paths.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh162Free2021-07-17Windows Process Execution of SyncAppvPublishingServer.vbs with Inline PowerShell Commands
Flags Windows executions of SyncAppvPublishingServer.vbs with a semicolon-augmented command line consistent with embedded PowerShell.
frack113, Huntrule TeamWindowsprocess_creationMedium191Free2021-07-16PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
Bhabesh Raj, Huntrule TeamWindowsps_scriptHigh325Free2021-07-16Windows: Suspicious Parent-Serv-U.exe Command-Line Process Spawning
Alerts when Serv-U (\Serv-U.exe) spawns typical command interpreters or execution utilities on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh253Free2021-07-14Windows reg.exe Used to Modify Security Service Start Parameters
Flags reg.exe registry changes that target Start parameters for common security and Windows Defender-related services.
Florian Roth (Nextron Systems), John Lambert (idea), elhoim, Huntrule TeamWindowsprocess_creationHigh459Free2021-07-14Suspicious PowerShell Execution From Windows Temporary Folders on Windows
Alerts when PowerShell runs with command-line paths pointing to Windows temp directories, excluding some common benign installers.
Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton, Huntrule TeamWindowsprocess_creationMedium347Free2021-07-14Windows ProtocolHandler.exe Download via Embedded URL Schemes
Flags ProtocolHandler.exe executions with ftp/http/https URLs that indicate automated downloading on Windows.
frack113, Huntrule TeamWindowsprocess_creationMedium152Free2021-07-13Windows PowerShell: AtomicTestHarness Invoke-ATHRemoteFXvGPUDisablementCommand Abuse
Alerts on Windows process command lines invoking AtomicTestHarnesses RemoteFXvGPUDisablement PowerShell execution.
frack113, Huntrule TeamWindowsprocess_creationHigh203Free2021-07-13Windows: InfDefaultInstall.exe .inf Execution
Flags Windows process executions of InfDefaultInstall.exe that include an .inf argument in the command line.
frack113, Huntrule TeamWindowsprocess_creationMedium181Free2021-07-13Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsps_moduleHigh537Free2021-07-13Windows PowerShell ModuleContents Set to Get-VMRemoteFXPhysicalVideoAdapter
Alerts on PowerShell module creation embedding Get-VMRemoteFXPhysicalVideoAdapter, a potential precursor to RemoteFXvGPUDisablement.exe abuse.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowspowershell-classicHigh452Free2021-07-13Windows Uninstall CrowdStrike Falcon Sensor via WindowsSensor.exe /uninstall /quiet
Flags Windows processes uninstalling CrowdStrike Falcon Sensor using WindowsSensor.exe with /uninstall and /quiet.
frack113, Huntrule TeamWindowsprocess_creationHigh203Free2021-07-12Windows Process: SyncAppvPublishingServer.exe Executes PowerShell via PowerShell-encoded command
Alerts when SyncAppvPublishingServer.exe is launched with a command-line pattern indicative of PowerShell code execution.
frack113, Huntrule TeamWindowsprocess_creationMedium226Free2021-07-12Windows Process Injection via Mavinject Using INJECTRUNNING Flag
Alerts on Windows process creation using Mavinject with /INJECTRUNNING, indicative of DLL injection into a running process.
frack113, Florian Roth, Huntrule TeamWindowsprocess_creationHigh307Free2021-07-12