Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
Alerts on obfuscated PowerShell launcher patterns in Windows service creation events (EID 4697) consistent with VAR++ LAUNCHER.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityHigh152Free2020-10-13Windows Security Log: Obfuscated cmd Execution of clip.exe via PowerShell Clipboard Patterns (EID 4697)
Alerts on service creation (Windows 4697) with CLIP.exe command-line patterns that indicate obfuscated PowerShell execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh163Free2020-10-13Windows Proxy Execution via wuauclt.exe (UpdateDeploymentProvider/RunHandlerComServer)
Alerts when wuauclt.exe is executed with UpdateDeploymentProvider/RunHandlerComServer-related parameters indicative of proxy execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Florian Roth (Nextron Systems), Sreeman, FPT.EagleEye Team, Huntrule TeamWindowsprocess_creationHigh238Free2020-10-12Windows WMIC process creation with suspicious command execution
Alerts on WMIC spawning new processes with command-line indicators of common execution/payload binaries on Windows.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh132Free2020-10-12Windows regini.exe Used to Modify Registry via Alternate Data Streams (ADS)
Alert on regini.exe process executions whose command line contains an ADS-style colon pattern used for registry modification.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh199Free2020-10-12Windows: regedit.exe imports .reg via an alternate data stream (ADS)
Alerts when regedit.exe is used to import a .reg file using an alternate data stream pattern in the command line.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2020-10-12Windows Regedit Exports Registry Hives to Files
Flags regedit.exe command lines exporting SYSTEM/SAM/SECURITY hives from HKLM to files.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh322Free2020-10-12Windows Process Creation: PowerShell or sc.exe Disabling Windows Defender Behavior Monitoring
Detects PowerShell flags or sc.exe service actions that disable WinDefend monitoring on Windows.
ok @securonix invrep-de, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh164Free2020-10-12Windows Indirect Command Execution via Program Compatibility Assistant pcwrun.exe
Alerts on child processes spawned by pcwrun.exe, indicating indirect command execution via Program Compatibility Assistant.
A. Sungurov , oscd.community, Huntrule TeamWindowsprocess_creationLow171Free2020-10-12Detect Obfuscated PowerShell Command Invocation via Stdin on Windows
Flags PowerShell-like command-line patterns indicating obfuscated execution using stdin or input substitution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh313Free2020-10-12Windows Process Creation: AtBroker.exe Launching Assistive Technology Apps
Alerts on Windows process starts of AtBroker.exe with "start" that don’t match known built-in accessibility parameters.
Mateusz Wydra, oscd.community, Huntrule TeamWindowsprocess_creationMedium111Free2020-10-12PowerShell Obfuscation Delivered via Stdin Using Set-and-Invoke Pattern
Detects obfuscated PowerShell script blocks that use chained stdin/environment/input patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh4610Free2020-10-12PowerShell Module: Obfuscated Script Execution via Stdin Pattern
Detects obfuscated PowerShell module payloads using chained set and stdin/input invoke patterns.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh386Free2020-10-12Windows WMIPRVSE DLL Hijack via Network-Created wbemcomn.dll in System32\wbem
Flags wmiprvse.exe loading wbemcomn.dll from the System32\wbem directory, consistent with a WMI DLL hijack.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadHigh125Free2020-10-12Windows DCOM InternetExplorer.Application DLL Hijack via iertutil.dll Image Load
Alerts when iexplore.exe loads iertutil.dll from an Internet Explorer path, indicating possible DLL hijacking.
Roberto Rodriguez @Cyb3rWard0g, Open Threat Research (OTR), wagga, Huntrule TeamWindowsimage_loadCritical183Free2020-10-12