Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Identify RpcPing.exe -s RPC test that requests NTLM authentication
Detects RpcPing.exe RPC test usage with parameters indicating NTLM authentication attempts.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium152Free2020-10-09Windows Renamed ftp.exe Execution via OriginalFileName PE Metadata
Flags Windows executions where PE OriginalFileName is ftp.exe but the image path is not named ftp.exe.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium237Free2020-10-09Suspicious WINWORD.exe DLL loading via /l flag and .dll path on Windows
Flags WINWORD.exe runs that include /l and a .dll indicator, suggesting potential DLL sideloading on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium143Free2020-10-09Windows: Detect Runscripthelper.exe executing PowerShell scripts with 'surfacecheck'
Detects Runscripthelper.exe executions with "surfacecheck" in the command line on Windows.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium142Free2020-10-09Windows Rasautou.exe DLL loading with -d and export execution via -p
Flags Rasautou.exe running with -d and -p to load a DLL and execute a specified export.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium383Free2020-10-09Windows Process Creation: PowerShell Obfuscation Executed via Clip.exe and Clipboard
Flags Windows command lines indicating clip.exe clipboard use followed by obfuscated PowerShell invoke behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh231Free2020-10-09Windows Arbitrary File Download via GfxDownloadWrapper.exe URL Argument Execution
Flags GfxDownloadWrapper.exe executions that include http/https URLs for downloading files, excluding a known Intel gameplay API URL.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium261Free2020-10-09Windows: Detect ftp.exe Executed With -s or /s for Script-Based Command Execution
Flags Windows executions of ftp.exe using -s or /s, indicating potential scripted command abuse.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium227Free2020-10-09PowerShell Script Obfuscation Triggered by Use of clip.exe and Clipboard Invocation
Flags PowerShell Script Block Logging containing clip.exe/clipboard chaining and clipboard-driven execution markers.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh246Free2020-10-09PowerShell module obfuscation using clip.exe with echo and clipboard invocation
Flags obfuscated PowerShell module scripts that echo “clip” and invoke clipboard-related behavior.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh161Free2020-10-09Windows PowerShell: Detect Suspicious Opsec Artifacts in Script Module Content
Identifies PowerShell module content containing frequent offensive payload string markers associated with poor operational security.
ok @securonix invrep_de, oscd.community, Huntrule TeamWindowsps_moduleCritical445Free2020-10-09Windows Service Control Manager Rundll32 Obfuscation via Command-Line Encoded PowerShell
Detects service creation where ImagePath invokes rundll32 (shell32) with command-chain tokens indicative of obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh110Free2020-10-09Windows System: mshta Launches vbscript:createobject via Service Control Manager (Event ID 7045)
Flags Windows service creation (7045) where ImagePath includes mshta and vbscript:createobject.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh213Free2020-10-09Windows System: Suspicious Clip.exe Execution via Service Control Manager (Event ID 7045)
Alerts on Windows service creation starting clipboard/Clip.exe-related binaries via Service Control Manager ImagePath.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssystemHigh232Free2020-10-09Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh132Free2020-10-09