Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,354 rules
PowerShell Script Execution via Windows Service Creation (Service Control Manager)
Flags service creation/start events where the service ImagePath references PowerShell (powershell/pwsh).
oscd.community, Natalia Shornikova, Huntrule TeamWindowssystemHigh463Free2020-10-06Windows Service Creation of PowerShell/Pwsh Scripts (Security EID 4697)
Alerts on service creation events where the service executable name includes powershell or pwsh.
oscd.community, Natalia Shornikova, Huntrule TeamWindowssecurityHigh182Free2020-10-06Non-privileged reg.exe or PowerShell registry service configuration changes on Windows
Flags non-admin reg.exe or PowerShell activity targeting service registry configuration paths on Windows.
Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community, Huntrule TeamWindowsprocess_creationHigh439Free2020-10-05Windows Print Executable Misuse via print.exe Command-Line
Flags suspicious print.exe invocations using /D and .exe, excluding command lines that explicitly contain print.exe.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Huntrule TeamWindowsprocess_creationMedium274Free2020-10-05Windows: Rundll32 LaunchApplication via pcwutl.dll
Flags rundll32.exe using pcwutl.dll to invoke LaunchApplication.
Julia Fomina, oscd.community, Huntrule TeamWindowsprocess_creationMedium163Free2020-10-05Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Alerts when Windows process command lines include Hydra -u/-p parameters with USER/PASS placeholders.
Vasiliy Burov, Huntrule TeamWindowsprocess_creationHigh141Free2020-10-05Windows findstr.exe Subfolder and Case-Insensitive Search Flags
Alerts on findstr.exe executions that include both -s (subfolders) and -i (case-insensitive) flags.
Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationLow142Free2020-10-05Windows: SyncAppvPublishingServer.exe execution via PowerShell script block content
Flags PowerShell script blocks that reference SyncAppvPublishingServer.exe, indicating possible execution via a PowerShell-restricted workflow.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_scriptMedium141Free2020-10-05Windows SyncAppvPublishingServer Execution Triggering PowerShell Module Context
Alerts when SyncAppvPublishingServer.exe appears in PowerShell module ContextInfo on Windows.
Ensar Şamil, @sblmsrsn, OSCD Community, Huntrule TeamWindowsps_moduleMedium465Free2020-10-05Windows Security: Suspicious Remote Logon Using Explicit Credentials via Command-Line Tools
Flags EventID 4648 remote logons initiated by cmd/PowerShell/winrs/wmic/net/reg-style processes using explicit credentials.
oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton, Huntrule TeamWindowssecurityMedium81Free2020-10-05Windows: Manual persistence attempt using schtasks to run Microsoft Compatibility Appraiser
Alerts when schtasks runs "Microsoft Compatibility Appraiser" via Application Experience, consistent with persistence abuse.
Sreeman, Huntrule TeamWindowsprocess_creationMedium126Free2020-09-29Windows service configuration tampering via sc/reg with payload execution paths
Looks for sc/reg command-line activity that updates Windows service ImagePath or FailureCommand to run attacker-controlled payloads.
Sreeman, Huntrule TeamWindowsprocess_creationMedium227Free2020-09-29Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)
Flags HKCU DelegateExecute registry changes for COM hijack style persistence under the Folder shell open command.
Omkar Gudhate, Huntrule TeamWindowsregistry_setHigh121Free2020-09-27Windows VirtualBox Driver Registration or VM Startup via Process Command Line
Alerts on Windows processes whose command lines reference VirtualBox driver registration or VM start/control actions.
Janantha Marasinghe, Huntrule TeamWindowsprocess_creationLow186Free2020-09-26Windows NetLogon Secure Channel Connection Allowed for Vulnerable Client
Alerts on Windows NetLogon ETW events indicating an allowed secure channel connection (Event ID 5829).
NVISO, Huntrule TeamWindowssystemHigh102Free2020-09-15