Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,357 rules
Windows Process Execution and DLL Injection via Tracker.exe
Alerts on Tracker.exe executions with /d and /c command-line switches, excluding matching MSBuild child process patterns.
Avneet Singh @v3t0_, oscd.community, Huntrule TeamWindowsprocess_creationMedium162Free2020-10-18Windows: msdeploy.exe Execution with sync and RunCommand Parameters
Flags msdeploy.exe executions that include sync verb plus RunCommand source and destination parameters.
Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationMedium91Free2020-10-18Windows PowerShell Process Creation: COMPRESS OBFUSCATION with ASCII Encoding and DeflateStream
Flags PowerShell process creation command lines that use ASCII encoding plus compression/stream-reading patterns associated with obfuscation.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium426Free2020-10-18Windows: Dotnet.exe executes arbitrary DLL or csproj files
Alerts when dotnet.exe runs with .csproj or .dll arguments that may indicate loading or execution of untrusted .NET code.
Beyu Denis, oscd.community, Huntrule TeamWindowsprocess_creationMedium81Free2020-10-18PowerShell ScriptBlock Logging: Obfuscated RUNDLL Launcher using rundll32.exe and shell32.dll
Identifies PowerShell script content invoking rundll32.exe/shell32.dll via shellexec_rundll and referencing PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium152Free2020-10-18Detect PowerShell COMPRESS OBFUSCATION using ASCII text encoding and stream/compression APIs
Flags PowerShell script blocks that combine ASCII encoding with Deflate/stream handling indicative of obfuscated payload compression.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium394Free2020-10-18PowerShell module activity launching rundll32 via shell32.dll obfuscation content
Alerts when PowerShell module payloads reference a shell32/rundll32 launcher pattern that includes PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleMedium173Free2020-10-18PowerShell Module Payload Obfuscation Using COMPRESS OBFUSCATION
Identifies PowerShell module payloads containing ASCII encoding and compression/stream obfuscation strings.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleMedium438Free2020-10-18Windows System: Detect rundll32 Service Control Manager launches PowerShell via obfuscated parameters
Flags service creation where ImagePath uses rundll32/shell32 (shellexec_rundll) to invoke PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemMedium80Free2020-10-18Windows System: Service Control Manager PowerShell Obfuscation Using COMPRESS OBFUSCATION
Flags new Windows services whose ImagePath includes obfuscated PowerShell markers using COMPRESS/stream decompression.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemMedium173Free2020-10-18Windows Security 4697: Obfuscated PowerShell via rundll32 shell32 shellexec_rundll
Alert on Security EID 4697 where service installation references rundll32/shell32.dll to launch PowerShell.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityMedium80Free2020-10-18Windows Security 4697 PowerShell obfuscated content using COMPRESS OBFUSCATION components
Alerts on service creation events where the ServiceFileName includes PowerShell obfuscation patterns tied to compression stream and ASCII encoding.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityMedium141Free2020-10-18Windows PowerShell Script Execution via Redirected Input Stream
Flags PowerShell/pwsh executions where the command line includes redirected input ("- <").
Moriarty Meng (idea), Anton Kutepov (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh204Free2020-10-17Windows Process Creation: Suspicious Microsoft Csi.exe or Rcsi.exe with C# Execution Capability
Alerts on Windows executions of Microsoft’s csi.exe/rcsi.exe that can be used to run C# code from command-line.
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium153Free2020-10-17Windows WMIC loading JavaScript/VBScript engine libraries
Alerts on wmic.exe loading jscript.dll or vbscript.dll, a common sign of script execution via Windows Management Instrumentation.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium454Free2020-10-17