Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh112Free2020-10-09Windows Security EID 4697: mshta Used to Run Obfuscated VBScript PowerShell
Detects service creation where the binary path includes mshta plus VBS/automation indicators consistent with script-based obfuscation.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh143Free2020-10-09Windows Security 4697: Obfuscated PowerShell via use of Clip.exe from scripts
Alerts on EID 4697 service installations where the service file name matches Clip/clipboard indicators tied to obfuscated PowerShell.
Nikita Nazarov, oscd.community, Huntrule TeamWindowssecurityHigh182Free2020-10-09Windows regini.exe Execution Leading to Registry Key Changes
Alerts on Windows executions of regini.exe that can import registry changes from text files.
Eli Salem, Sander Wiebing, oscd.community, Huntrule TeamWindowsprocess_creationLow181Free2020-10-08Windows net.exe Unmount Share (/delete) Execution
Alerts on net.exe/net1.exe commands that include "share" and "/delete", indicating share unmount/removal on Windows.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsprocess_creationLow152Free2020-10-08Windows Process Dumping via sqldumper.exe with 0x0110 Command-Line Flags
Alerts on sqldumper.exe executions with command-line dump parameters indicative of process dumping.
Kirill Kiryanov, oscd.community, Huntrule TeamWindowsprocess_creationMedium91Free2020-10-08Windows: Code Execution via Pester.bat Using PowerShell Help or cmd.exe
Flags Windows process executions that invoke Pester-related help/commands via PowerShell or cmd, consistent with Pester.bat usage.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium100Free2020-10-08Windows Process Execution: Obfuscated PowerShell Invocation Using mshta with VBScript CreateObject
Flags Windows process command lines containing an obfuscated PowerShell+MSHTA VBScript execution pattern.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh226Free2020-10-08PowerShell share removal via Remove-SmbShare or Remove-FileShare on Windows
Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.
oscd.community, @redcanary, Zach Stanford @svch0st, Huntrule TeamWindowsps_scriptMedium215Free2020-10-08PowerShell ScriptBlock Obfuscation via MSHTA VBScript CreateObject Execution
Alerts on PowerShell script blocks containing mshta and VBScript createobject/.run/window.close patterns consistent with obfuscated execution.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_scriptHigh153Free2020-10-08PowerShell Module: Obfuscated MSHTA Invocation via VBS CreateObject
Alerts when PowerShell module payload text includes an obfuscated MSHTA/VBScript invocation sequence.
Nikita Nazarov, oscd.community, Huntrule TeamWindowsps_moduleHigh351Free2020-10-08UAC Bypass Using wsreset.exe Registry Command Path (Windows)
Identifies registry TargetObject values associated with a wsreset-style UAC bypass execution command path on Windows.
oscd.community, Dmitry Uchakin, Huntrule TeamWindowsregistry_eventHigh161Free2020-10-07Xwizard.EXE COM Execution with RunWizard and GUID Argument (Windows)
Alerts when Xwizard.EXE runs with RunWizard plus a GUID-like argument on Windows, consistent with COM execution usage.
Ensar Şamil, @sblmsrsn, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium254Free2020-10-07Windows: Remote code execution via winrm.vbs using cscript and wmicimv2/Win32_ Create
Alerts on cscript.exe executions referencing winrm and wmicimv2/Win32_ Create with -r:http, consistent with remote code execution via winrm.vbs.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium146Free2020-10-07Rundll32 Executes Setupapi.dll InstallHinfSection via Runonce.exe
Alerts when rundll32 passes setupapi.dll::InstallHinfSection arguments that result in launching runonce.exe.
Konstantin Grishchenko, oscd.community, Huntrule TeamWindowsprocess_creationMedium335Free2020-10-07