Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,357 rules
PowerShell Module: Obfuscated Clip.exe launcher using cmd with clipboard download payload
Detects obfuscated PowerShell module commands that run cmd with clip.exe/clipboard payload formatting.
Jonathan Cheong, oscd.community, Huntrule TeamWindowsps_moduleHigh218Free2020-10-13Windows System: Detects Service Control Manager spawning obfuscated PowerShell via VAR++ LAUNCHER
Flags newly created Windows services whose ImagePath contains cmd chaining and obfuscated PowerShell launcher indicators.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssystemHigh414Free2020-10-13Windows System Service Control: Obfuscated cmd Launching clip.exe for PowerShell
Flags service creation (Event 7045) with obfuscated cmd ImagePath using clip.exe/clipboard PowerShell execution patterns.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssystemHigh60Free2020-10-13Windows Zerologon Exploitation Attempts via Mimikatz or Tools from Kali Host
Identifies Windows Zerologon exploitation attempts tied to Kali-hosted activity and mimikatz-related keywords.
Demyan Sokolin @_drd0c, Teymur Kheirkhabarov @HeirhabarovT, oscd.community, Huntrule TeamWindowssystemCritical499Free2020-10-13Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
Alerts on obfuscated PowerShell launcher patterns in Windows service creation events (EID 4697) consistent with VAR++ LAUNCHER.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowssecurityHigh152Free2020-10-13Windows Security Log: Obfuscated cmd Execution of clip.exe via PowerShell Clipboard Patterns (EID 4697)
Alerts on service creation (Windows 4697) with CLIP.exe command-line patterns that indicate obfuscated PowerShell execution.
Jonathan Cheong, oscd.community, Huntrule TeamWindowssecurityHigh163Free2020-10-13Windows Proxy Execution via wuauclt.exe (UpdateDeploymentProvider/RunHandlerComServer)
Alerts when wuauclt.exe is executed with UpdateDeploymentProvider/RunHandlerComServer-related parameters indicative of proxy execution.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Florian Roth (Nextron Systems), Sreeman, FPT.EagleEye Team, Huntrule TeamWindowsprocess_creationHigh238Free2020-10-12Windows WMIC process creation with suspicious command execution
Alerts on WMIC spawning new processes with command-line indicators of common execution/payload binaries on Windows.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2020-10-12Windows regini.exe Used to Modify Registry via Alternate Data Streams (ADS)
Alert on regini.exe process executions whose command line contains an ADS-style colon pattern used for registry modification.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh199Free2020-10-12Windows: regedit.exe imports .reg via an alternate data stream (ADS)
Alerts when regedit.exe is used to import a .reg file using an alternate data stream pattern in the command line.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2020-10-12Windows Regedit Exports Registry Hives to Files
Flags regedit.exe command lines exporting SYSTEM/SAM/SECURITY hives from HKLM to files.
Oddvar Moe, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationHigh322Free2020-10-12Windows Process Creation: PowerShell or sc.exe Disabling Windows Defender Behavior Monitoring
Detects PowerShell flags or sc.exe service actions that disable WinDefend monitoring on Windows.
ok @securonix invrep-de, oscd.community, frack113, Huntrule TeamWindowsprocess_creationHigh164Free2020-10-12Windows Indirect Command Execution via Program Compatibility Assistant pcwrun.exe
Alerts on child processes spawned by pcwrun.exe, indicating indirect command execution via Program Compatibility Assistant.
A. Sungurov , oscd.community, Huntrule TeamWindowsprocess_creationLow171Free2020-10-12Detect Obfuscated PowerShell Command Invocation via Stdin on Windows
Flags PowerShell-like command-line patterns indicating obfuscated execution using stdin or input substitution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh313Free2020-10-12Windows Process Creation: AtBroker.exe Launching Assistive Technology Apps
Alerts on Windows process starts of AtBroker.exe with "start" that don’t match known built-in accessibility parameters.
Mateusz Wydra, oscd.community, Huntrule TeamWindowsprocess_creationMedium111Free2020-10-12