Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
PowerShell command-line obfuscation indicators from special-character patterns (Windows)
Alerts on PowerShell executions whose command lines contain repeated special-character obfuscation patterns.
Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton (fp), Huntrule TeamWindowsprocess_creationHigh3810Free2020-10-15Windows Process Creation: Cmd Invokes PowerShell via Obfuscated Environment Variable Expansion
Alerts on cmd.exe command lines that use obfuscated environment-variable SET to execute PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh172Free2020-10-15Windows Process Execution Using Obfuscated CMD to Pipe STDIN into PowerShell
Detects obfuscated cmd executions that launch PowerShell and reference $input/noexit patterns for STDIN-based execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh173Free2020-10-15PowerShell: Obfuscated invocation via Environment Variables in Script Block
Alerts on PowerShell script blocks launching cmd /c or /r with obfuscated set-and-{n} variable expansion patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh141Free2020-10-15PowerShell Obfuscated stdin launcher using cmd /c or cmd /r patterns
Detects PowerShell script blocks that use obfuscated STDIN-driven cmd/powershell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh2610Free2020-10-15PowerShell Module: Obfuscated Environment Variable Expansion via cmd /c set -f Pattern
Alerts when PowerShell module payloads obfuscate execution via cmd /c|/r and environment-variable-based set patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh193Free2020-10-15PowerShell Module: Obfuscated STDIN Execution via cmd /c or cmd /r
Alerts when an obfuscated cmd->PowerShell payload uses stdin-style input and noexit/no-execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh181Free2020-10-15Windows Service Control Manager: Obfuscated Environment Variable PowerShell via cmd /c set -f
Alerts on Service Control Manager event 7045 where a service ImagePath uses cmd /c|/r with "set" and -f formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh202Free2020-10-15Windows System Service Control Manager spawning cmd with PowerShell and stdin input obfuscation
Flags SCM-created services whose ImagePath runs cmd to invoke PowerShell using stdin/input and -NoExit patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh90Free2020-10-15Windows Security 4697: cmd.exe Launching Obfuscated PowerShell via Environment Variable Expansion
Alerts on EID 4697 service installation command lines containing obfuscated cmd.exe SET patterns used to execute PowerShell via environment variables.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh133Free2020-10-15Windows Security Event 4697 PowerShell Launch via cmd/stdin Obfuscation
Alerts on service creation events that run PowerShell through cmd with stdin-style obfuscation markers.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh90Free2020-10-15Windows: Malicious Child Process Execution via vsjitdebugger.exe Just-In-Time Debugger
Flags unusual executables launched by vsjitdebugger.exe on Windows, excluding common Visual Studio helper/debugger children.
Agro (@agro_sev), Ensar Şamil (@sblmsrsn), oscd.community, Huntrule TeamWindowsprocess_creationMedium363Free2020-10-14Windows Process Execution Proxy Using SyncInvoke in CL_Invocation.ps1
Alerts on Windows command lines containing "SyncInvoke" consistent with CL_Invocation.ps1 execution proxy behavior.
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_creationMedium271Free2020-10-14Windows Script and LOLBins Loading .NET CLR DLLs via clr.dll, mscoree.dll, mscorlib.dll
Alerts when common scripting/execution binaries load .NET CLR DLLs like clr.dll and mscoree.dll on Windows.
omkar72, oscd.community, Huntrule TeamWindowsimage_loadHigh4410Free2020-10-14Windows Registry-Based DLL Hijack via WAB.EXE Using WAB Registry DLLPath
Flags WAB.EXE DLLPath registry writes where the configured DLL path differs from the default.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh82Free2020-10-13