Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,357 rules
Windows: Malicious Child Process Execution via vsjitdebugger.exe Just-In-Time Debugger
Flags unusual executables launched by vsjitdebugger.exe on Windows, excluding common Visual Studio helper/debugger children.
Agro (@agro_sev), Ensar Şamil (@sblmsrsn), oscd.community, Huntrule TeamWindowsprocess_creationMedium363Free2020-10-14Windows Process Execution Proxy Using SyncInvoke in CL_Invocation.ps1
Alerts on Windows command lines containing "SyncInvoke" consistent with CL_Invocation.ps1 execution proxy behavior.
Nasreddine Bencherchali (Nextron Systems), oscd.community, Natalia Shornikova, Huntrule TeamWindowsprocess_creationMedium271Free2020-10-14Windows Script and LOLBins Loading .NET CLR DLLs via clr.dll, mscoree.dll, mscorlib.dll
Alerts when common scripting/execution binaries load .NET CLR DLLs like clr.dll and mscoree.dll on Windows.
omkar72, oscd.community, Huntrule TeamWindowsimage_loadHigh4410Free2020-10-14Windows Registry-Based DLL Hijack via WAB.EXE Using WAB Registry DLLPath
Flags WAB.EXE DLLPath registry writes where the configured DLL path differs from the default.
oscd.community, Natalia Shornikova, Huntrule TeamWindowsregistry_setHigh82Free2020-10-13Windows Process Creation: accesschk.exe Permission Audit Execution
Flags AccessChk (accesschk.exe) permission/audit executions using common query flags in Windows process creation logs.
Teymur Kheirkhabarov (idea), Mangatas Tondang, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium2310Free2020-10-13Windows te.exe Execution of Test Components (TAEF) via Process Creation
Alerts on process activity involving te.exe, which may indicate TAEF-based execution of malicious test components.
Agro (@agro_sev) oscd.community, Huntrule TeamWindowsprocess_creationLow101Free2020-10-13Windows msiexec.exe Installer Process Spawning cmd.exe or PowerShell
Flags installer-initiated spawning of cmd.exe or PowerShell from Windows\Installer temporary msi-related processes.
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule TeamWindowsprocess_creationMedium309Free2020-10-13Detect Elevated Windows Installer (msiexec) Running as SYSTEM
Flags msiexec.exe MSI activity from Windows Installer running with SYSTEM integrity, excluding known benign parent contexts.
Teymur Kheirkhabarov (idea), Mangatas Tondang (rule), oscd.community, Huntrule TeamWindowsprocess_creationMedium125Free2020-10-13Windows PowerShell via sqltoolsps.exe (sqltoolsps.exe child process exclusion)
Flags suspicious sqltoolsps.exe executions that may launch PowerShell, excluding cases where smss.exe spawned the utility.
Agro (@agro_sev) oscd.communitly, Huntrule TeamWindowsprocess_creationMedium342Free2020-10-13Windows manage-bde.wsf via wscript/cscript Proxy Execution
Flags Windows process executions where wscript/cscript runs manage-bde.wsf, indicating potential proxy execution via LOLBIN.
oscd.community, Natalia Shornikova, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh121Free2020-10-13Windows Process Command Line: Detect VAR++ LAUNCHER Obfuscated PowerShell
Flags Windows command lines showing VAR++ launcher-style obfuscated PowerShell execution through Invoke-Expression patterns.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationHigh3910Free2020-10-13Windows Process Creation: Obfuscated Cmd Uses clip.exe to Execute PowerShell
Alerts when cmd.exe uses obfuscated Clip.exe/clipboard calls to launch PowerShell.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsprocess_creationHigh245Free2020-10-13Detect VAR++ LAUNCHER-Style Obfuscated PowerShell Command Block
Detects VAR++ LAUNCHER-like PowerShell obfuscation patterns in ScriptBlockText.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptHigh4210Free2020-10-13PowerShell Script Block Obfuscation via cmd/clipboard and clip.exe execution
Identifies obfuscated PowerShell script blocks launching clip.exe and chaining clipboard-related execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_scriptHigh163Free2020-10-13PowerShell Module: VAR++ LAUNCHER Obfuscation in Obfuscated Command Payload
Identifies obfuscated PowerShell module payloads matching a VAR++ LAUNCHER-style invocation pattern.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_moduleHigh92Free2020-10-13