Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
PowerShell ScriptBlock Logging: Obfuscated RUNDLL Launcher using rundll32.exe and shell32.dll
Identifies PowerShell script content invoking rundll32.exe/shell32.dll via shellexec_rundll and referencing PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium152Free2020-10-18Detect PowerShell COMPRESS OBFUSCATION using ASCII text encoding and stream/compression APIs
Flags PowerShell script blocks that combine ASCII encoding with Deflate/stream handling indicative of obfuscated payload compression.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium394Free2020-10-18PowerShell module activity launching rundll32 via shell32.dll obfuscation content
Alerts when PowerShell module payloads reference a shell32/rundll32 launcher pattern that includes PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleMedium173Free2020-10-18PowerShell Module Payload Obfuscation Using COMPRESS OBFUSCATION
Identifies PowerShell module payloads containing ASCII encoding and compression/stream obfuscation strings.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleMedium438Free2020-10-18Windows System: Detect rundll32 Service Control Manager launches PowerShell via obfuscated parameters
Flags service creation where ImagePath uses rundll32/shell32 (shellexec_rundll) to invoke PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemMedium80Free2020-10-18Windows System: Service Control Manager PowerShell Obfuscation Using COMPRESS OBFUSCATION
Flags new Windows services whose ImagePath includes obfuscated PowerShell markers using COMPRESS/stream decompression.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemMedium173Free2020-10-18Windows Security 4697: Obfuscated PowerShell via rundll32 shell32 shellexec_rundll
Alert on Security EID 4697 where service installation references rundll32/shell32.dll to launch PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityMedium80Free2020-10-18Windows Security 4697 PowerShell obfuscated content using COMPRESS OBFUSCATION components
Alerts on service creation events where the ServiceFileName includes PowerShell obfuscation patterns tied to compression stream and ASCII encoding.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityMedium141Free2020-10-18Windows PowerShell Script Execution via Redirected Input Stream
Flags PowerShell/pwsh executions where the command line includes redirected input ("- <").
Moriarty Meng (idea), Anton Kutepov (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh224Free2020-10-17Windows Process Creation: Suspicious Microsoft Csi.exe or Rcsi.exe with C# Execution Capability
Alerts on Windows executions of Microsoft’s csi.exe/rcsi.exe that can be used to run C# code from command-line.
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium153Free2020-10-17Windows WMIC loading JavaScript/VBScript engine libraries
Alerts on wmic.exe loading jscript.dll or vbscript.dll, a common sign of script execution via Windows Management Instrumentation.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium454Free2020-10-17Potential Windows Registry Persistence via AppCompatFlags TelemetryController Commands
Flags registry entries under TelemetryController\Command that reference executable/script payloads potentially abusing telemetry for persistence.
Lednyov Alexey, oscd.community, Sreeman, Huntrule TeamWindowsregistry_setHigh516Free2020-10-16Windows sc.exe Security Descriptor Tampering to Deny Service Access via sdset
Alerts on sc.exe sdset commands that modify service security descriptors to deny access to critical trustees.
Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationHigh130Free2020-10-16Windows Process: reg.exe Software Version Discovery via svcVersion Query
Alerts when reg.exe is used to query \Software\ for svcVersion, indicating Windows software version discovery.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationMedium132Free2020-10-16Windows PowerShell Software Enumeration via Script Block Content
Flags PowerShell registry queries for installed software metadata combined with selection and table formatting.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptMedium467Free2020-10-16